Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.
Published: 2026-07-13
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input validation flaw in Zorem Advanced Shipment Tracking for WooCommerce allows an attacker to inject malicious SQL code into a query without immediate error feedback. The flaw is classified as CWE-89. Based on the description, it is inferred that this results in blind SQL injection, meaning that while the attacker may not see query output, they may infer data from application responses or manipulate the database content. Successful exploitation can lead to retrieval of sensitive information such as order details, customer data, or credentials, and may grant the attacker unauthorized data modification capabilities.

Affected Systems

The vulnerability affects the WordPress plugin Zorem Advanced Shipment Tracking for WooCommerce, including all released versions up to and including 4.0. Users running any version of this plugin on a WordPress site are at risk unless the plugin has been upgraded beyond version 4.0 or otherwise mitigated.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity of exploitation impact. The EPSS score of less than 1% implies a very low probability of widespread exploitation at this time. The vulnerability is currently not listed in the CISA KEV catalog. Attackers would most likely leverage the web interface of the plugin, sending specially crafted requests that trigger the underlying SQL queries. Because the injection is blind, an attacker can employ timing or inferred‑data techniques to extract information without explicit feedback. Responders should treat this as a high‑priority issue, given the potential for confidential data exposure and the simplicity of the exploit path.

Generated by OpenCVE AI on July 31, 2026 at 11:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Zorem Advanced Shipment Tracking for WooCommerce plugin to a version newer than 4.0 that contains the SQL injection fix.
  • If an upgrade is not immediately feasible, deactivate or completely disable the plugin to eliminate the vulnerability until a patched version is available.
  • Restrict the database permissions granted to the WordPress‑associated account, ensuring it only has the minimum privileges necessary for normal operation to limit potential damage from any residual injection flaw.

Generated by OpenCVE AI on July 31, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Zorem
Zorem advanced Shipment Tracking For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Zorem
Zorem advanced Shipment Tracking For Woocommerce

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.
Title WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Wordpress Wordpress
Zorem Advanced Shipment Tracking For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:23:28.120Z

Reserved: 2026-06-25T08:04:47.959Z

Link: CVE-2026-57773

cve-icon Vulnrichment

Updated: 2026-07-13T13:23:22.632Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')