PatchStack – https://patchstack.com/database/wordpress/plugin/woo-advanced-shipment-tracking/vulnerability/wordpress-advanced-shipment-tracking-for-woocommerce-plugin-4-0-sql-injection-vulnerability
CVE ID: CVE-2026-57773
WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 4.0 is vulnerable to SQL Injection
This security issue has a low severity impact and is unlikely to be exploited.
Hi @tonyh310, @sholly2
Thanks for the heads-up and for the detailed report — we appreciate you flagging it.
We’re already on it: we’ll be releasing an updated version with the fix by next Tuesday. As the Patchstack entry notes, it’s rated low severity and unlikely to be exploited, so there’s no immediate risk in the meantime, but we’re addressing it promptly to be safe.
I’ll let you know once the patched version is released so you can update. Thanks again for bringing it to our attention.
Best Regards,
Gaurav