PLUGIN SECURITY

Is Orders Tracking for WooCommerce safe?

Easily import/manage your tracking numbers, add tracking numbers to PayPal and send email notifications to customers.

What this plugin does

  • Slug: woo-orders-tracking
  • Author: VillaTheme
  • 10000+ active installs
  • 90/100 rating (58 reviews on wordpress.org)
  • 411614 all-time downloads
  • On WordPress.org since 2019-05-07

advanced shipment tracking for woocommerceorders tracking for woocommercewoocommerce order tracking pluginwoocommerce shipment trackingwoocommerce tracking number

Maintenance status

  • Last updated: 2026-08-20 6:55am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.0+

Known vulnerabilities

3 known CVEs on file for Orders Tracking for WooCommerce. Reported between 2021 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4039 Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.2.11 Improper Control of Generation of Code ('Code Injection') Medium 6.5 < 1.2.11 1.2.11 2024-05-09
CVE-2023-4216 Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.2.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Low 2.7 < 1.2.6 1.2.6 2023-08-14
CVE-2021-25062 Trakoo – Orders Tracking for WooCommerce [woo-orders-tracking] < 1.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.1.10 1.1.10 2021-12-27

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.