AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-12713

CRITICAL · CVSS 9.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WPCargo Track & Trace plugin for WordPress versions prior to 8.0.4 is vulnerable to SQL injection due to inadequate sanitization and escaping of user-supplied parameters in SQL statements. This flaw allows unauthenticated attackers to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to version 8.0.4 or later to mitigate this risk.

CVE
CVE-2026-12713
Severity
CRITICAL
CVSS
9.1
EPSS
0.26%
WordPress

Original NVD Description

The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.