CVE-2026-12713
WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
| Vendor | unknown |
| Product | wpcargo track & trace |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpcargo track & trace
Be the first to know when new unknown vulnerabilities affecting unknown wpcargo track & trace are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPCargo Track & Trace
0 < 8.0.4
References
Credits
Shivamani Vastrala WPScan