WPIntell

Source evidence

Security report: possible SQL injection

Advanced Shipment Tracking for WooCommerce · support · 2026-07-02T16:44:00+00:00

complaintsentiment
highseverity
1.0relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 33 rows with source links

15.2% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
tonyh310 unresolved
Hello, I’m using Advanced Shipment Tracking for WooCommerce (version 4.0). The iThemes/Solid Security Site Scanner has flagged a potential SQL injection vulnerability affecting versions ≤ 4.0 (reported today via Patchstack data). PatchStack – https://patchstack.com/database/wordpress/plugin/woo-advanced-shipment-tracking/vulnerability/wordpress-advanced-shipment-tracking-for-woocommerce-plugin-4-0-sql-injection-vulnerability CVE ID: CVE-2026-57773 WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 4.0 is vulnerable to SQL Injection This security issue has a low severity impact and is unlikely to be exploited. Hi @tonyh310 , @sholly2 Thanks for the heads-up and for the detailed report — we appreciate you flagging it. We’re already on it: we’ll be releasing an updated version with the fix by next Tuesday. As the Patchstack entry notes, it’s rated low severity and unlikely to be exploited, so there’s no immediate risk in the meantime, but we’re addressing it promptly to be safe. I’ll let you know once the patched version is released so you can update. Thanks again for bringing it to our attention. Best Regards, Gaurav

Comments

2 shown
ProActive 2026-07-02T21:42:00+00:00

PatchStack – https://patchstack.com/database/wordpress/plugin/woo-advanced-shipment-tracking/vulnerability/wordpress-advanced-shipment-tracking-for-woocommerce-plugin-4-0-sql-injection-vulnerability CVE ID: CVE-2026-57773 WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 4.0 is vulnerable to SQL Injection This security issue has a low severity impact and is unlikely to be exploited.

gaurav1092 2026-07-03T13:30:00+00:00

Hi @tonyh310 , @sholly2 Thanks for the heads-up and for the detailed report — we appreciate you flagging it. We’re already on it: we’ll be releasing an updated version with the fix by next Tuesday. As the Patchstack entry notes, it’s rated low severity and unlikely to be exploited, so there’s no immediate risk in the meantime, but we’re addressing it promptly to be safe. I’ll let you know once the patched version is released so you can update. Thanks again for bringing it to our attention. Best Regards, Gaurav