Executive brief
A security vulnerability exists in the Advanced Shipment Tracking for WooCommerce plugin, which is used by online stores to manage and share tracking information with customers. A malicious user with high-level administrative or shop manager privileges could exploit this flaw to gain unauthorized access to the website's database. This could lead to the theft of sensitive business information or customer data, potentially impacting the store's operations and reputation.
Technical details
The Advanced Shipment Tracking for WooCommerce plugin (versions 4.0 and below) is vulnerable to a Blind SQL Injection attack due to improper neutralization of special elements used in SQL commands. The vulnerability is classified as CWE-89 and resides in the 'woo-advanced-shipment-tracking' component. An attacker with 'Shop Manager' or higher privileges can exploit this over the network without user interaction. By sending specially crafted requests, the attacker can interact directly with the database to extract sensitive information. The issue is addressed in version 4.0.1.
Affected products
- Zorem Advanced Shipment Tracking for WooCommerce <= 4.0
Timeline
- 2026-02-01: other: Vulnerability reported by Nguyen Ba Khanh
- 2026-07-02: patched: Patch released in version 4.0.1
- 2026-07-13: disclosed: NVD publication date