Impact
TrackShip for WooCommerce version 1.9.1 and earlier contain an SQL Injection flaw that permits an attacker to inject arbitrary SQL through unsanitized input fields used in database queries, potentially allowing disclosure of sensitive data, modification of database contents, or execution of arbitrary commands if the database user has elevated privileges. The flaw originates from improper neutralization of special elements in SQL commands.
Affected Systems
WordPress sites running the TrackShip for WooCommerce plugin version 1.9.1 or earlier are susceptible. The plugin, provided by TrackShip, is widely deployed on WooCommerce stores; any WordPress installation with this plugin version is at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while the EPSS score of less than 1% suggests current exploitation probability is low and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the plugin operates in the public web front‑end, so an attacker can likely forge requests to trigger the SQL injection without authentication. The combination of high impact and low probability means administrators should promptly review and patch this plugin to avoid a data breach.
OpenCVE Enrichment
EUVD