wptaskforce Vulnerabilities and Affected Products
Vulnerabilities associated with wpcargo_track_\&_trace.
Products
Clear product- wpcargo_track_\&_trace2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-44004CRITICAL | WordPress WPCargo Track & Trace plugin <= 8.0.2 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows SQL Injection.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2. CWE-89Sep 17, 2024 | CVSS9.3v3.1 | EPSS0.462% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25003CRITICAL | WPCargo < 6.9.0 - Unauthenticated RCEThe WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE | CVSS9.8v3.1 | EPSS56.1% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |