Title: Security report: possible SQL injection
Last modified: July 2, 2026

---

# Security report: possible SQL injection

 *  [tonyh310](https://wordpress.org/support/users/tonyh310/)
 * (@tonyh310)
 * [1 month ago](https://wordpress.org/support/topic/security-report-possible-sql-injection/)
 * Hello,
 * I’m using Advanced Shipment Tracking for WooCommerce (version 4.0).
 * The iThemes/Solid Security Site Scanner has flagged a potential SQL injection
   vulnerability affecting versions ≤ 4.0 (reported today via Patchstack data).

Viewing 2 replies - 1 through 2 (of 2 total)

 *  [ProActive](https://wordpress.org/support/users/sholly2/)
 * (@sholly2)
 * [1 month ago](https://wordpress.org/support/topic/security-report-possible-sql-injection/#post-18954764)
 * PatchStack – [https://patchstack.com/database/wordpress/plugin/woo-advanced-shipment-tracking/vulnerability/wordpress-advanced-shipment-tracking-for-woocommerce-plugin-4-0-sql-injection-vulnerability](https://patchstack.com/database/wordpress/plugin/woo-advanced-shipment-tracking/vulnerability/wordpress-advanced-shipment-tracking-for-woocommerce-plugin-4-0-sql-injection-vulnerability)
 * CVE ID: [CVE-2026-57773](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-57773)
 * WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 4.0 is vulnerable
   to SQL Injection
 * This security issue has a low severity impact and is unlikely to be exploited.
 *  Plugin Author [gaurav1092](https://wordpress.org/support/users/gaurav1092/)
 * (@gaurav1092)
 * [1 month ago](https://wordpress.org/support/topic/security-report-possible-sql-injection/#post-18955320)
 * Hi [@tonyh310](https://wordpress.org/support/users/tonyh310/), [@sholly2](https://wordpress.org/support/users/sholly2/)
 * Thanks for the heads-up and for the detailed report — we appreciate you flagging
   it.
 * We’re already on it: we’ll be releasing an updated version with the fix by next
   Tuesday. As the Patchstack entry notes, it’s rated low severity and unlikely 
   to be exploited, so there’s no immediate risk in the meantime, but we’re addressing
   it promptly to be safe.
 * I’ll let you know once the patched version is released so you can update. Thanks
   again for bringing it to our attention.
 * Best Regards,
   Gaurav

Viewing 2 replies - 1 through 2 (of 2 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsecurity-report-possible-sql-injection%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/woo-advanced-shipment-tracking/assets/icon-256x256.png?rev
   =2166296)
 * [Advanced Shipment Tracking for WooCommerce](https://wordpress.org/plugins/woo-advanced-shipment-tracking/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woo-advanced-shipment-tracking/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woo-advanced-shipment-tracking/)
 * [Active Topics](https://wordpress.org/support/plugin/woo-advanced-shipment-tracking/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woo-advanced-shipment-tracking/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woo-advanced-shipment-tracking/reviews/)

 * 3 replies
 * 3 participants
 * Last reply from: [gaurav1092](https://wordpress.org/support/users/gaurav1092/)
 * Last activity: [1 month ago](https://wordpress.org/support/topic/security-report-possible-sql-injection/#post-18955320)
 * Status: not resolved