CVE-2026-12713
WPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_number
CVSS Score
9.1
EPSS Score
0.2%
EPSS Percentile
7th
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
| Vendor | unknown |
| Product | wpcargo track & trace |
| Published | Aug 6, 2026 |
| Last Updated | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpcargo track & trace
Be the first to know when new critical vulnerabilities affecting unknown wpcargo track & trace are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPCargo Track & Trace
0 < 8.0.4
References
Credits
Shivamani Vastrala WPScan