WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Order Tracking – WordPress Status Tracking Plugin

Order tracking, status and project management plugin. Create tickets and tracking numbers. Send email updates. Works standalone and with WooCommerce.

4Reported vulnerabilities
6.1Highest CVSS score
3.5.3Latest version
3,000+Active installs

What to do now

Update Order Tracking – WordPress Status Tracking Plugin to 3.3.12b or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 29, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-4471 Medium 6.1 0.6% 0 to 3.3.6 (inclusive) 3.3.7 August 31, 2023
CVE-2026-39602 Medium 5.3 0.2% 3.4.4 and earlier January 31, 2026
CVE-2023-4500 Medium 4.7 0.3% 3.3.6 and earlier 3.3.7 August 28, 2023
CVE-2024-43343 Medium 4.3 0.5% 3.3.11 and earlier 3.3.12b August 16, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.