CVE · Low

CVE-2023-4216 — Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4216 Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.2.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 2.7 < 1.2.6 1.2.6 2023-08-14

CVE-2023-4216

The Orders Tracking for WooCommerce plugin before version 1.2.6 contained a directory traversal flaw that could permit attackers to list files within directories or verify the existence of specific files and folders. An attacker could leverage this vulnerability to gain information useful for identifying and exploiting additional security weaknesses in the system. The vulnerability was resolved in version 1.2.6, and users should upgrade to this version or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.