Impact
The WPCargo Track & Trace WordPress plugin before version 8.0.4 does not correctly sanitise a configuration parameter used in a SQL query, allowing unauthenticated users to inject arbitrary SQL statements. The flaw is separate from the issue addressed by CVE‑2024‑44004 and can lead to reading, modifying, or deleting sensitive data stored in the WordPress database, thereby compromising confidentiality and integrity of site content.
Affected Systems
Any WordPress site running the WPCargo Track & Trace plugin with a version older than 8.0.4 is affected. No specific sub‑version range is listed beyond the <8.0.4 cutoff, so the vulnerability applies to all releases prior to 8.0.4.
Risk and Exploitability
Based on the description, it is inferred that an attacker can trigger the vulnerability by sending an HTTP request containing a crafted wpcargo_tracking_number value to the plugin’s tracking endpoint, which requires no authentication. This leads to a high risk of exploitation, as the flaw can expose or alter database contents. The CVSS score of 9.1 indicates a high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the potential impact remains significant.
OpenCVE Enrichment