Medium 5.3 Unfixed
2026-04-08≤ 3.4.4
CVE-2026-39602
Minimum safe version
3.3.13
Update to 3.3.13 or later to address 5 fixable vulnerabilities
CVE-2026-39602
CVE-2024-43343
CVE-2023-4500
CVE-2023-4471
WordPress Order Tracking plugin <= 3.0.16 - Authenticated Arbitrary Plugin Settings Update vulnerability
WordPress Order Tracking plugin <= 3.0.16 - Cross-Site Request Forgery (CSRF) leading to Order, Customer and Sales Representative Deletion