CyberRota Analysis
AI-GeneratedThe WPCargo Track & Trace plugin for WordPress versions prior to 8.0.4 is vulnerable to SQL injection due to inadequate sanitization and escaping of user-supplied parameters in SQL statements. This flaw allows unauthenticated attackers to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to version 8.0.4 or later to mitigate this risk.
Original NVD Description
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.