What is CVE-2026-12713?
The WPCargo Track & Trace WordPress plugin before version 8.0.4 fails to properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated SQL injection attacks. This affects a code path distinct from CVE-2024-44004, and immediate update to the latest version is advised.
Azərbaycanca: WPCargo Track & Trace WordPress plagininin 8.0.4 əvvəl versiyalarında kiritilən parametrin SQL sorğusunda istifadə olunmazdan əvvəl düzgün təmizlənməməsi autentifikasiyasız SQL injection hücumlarına imkan verir. Bu boşluq CVE-2024-44004-dən fərqli kod bölməsinə təsir göstərir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WPCargo Track & Trace plugin are affected by CVE-2026-12713?
This vulnerability affects the WPCargo Track & Trace WordPress plugin in versions before 8.0.4.
Is authentication required to exploit CVE-2026-12713?
No, the vulnerability allows unauthenticated SQL injection attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.