Beta

Report

WPCargo Track & Trace <= 6.8.9 is vulnerable to Unauthenticated Remote Code Execution (RCE) vulnerability

Unauthenticated
Published
2022-02-20

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

CVSS

Score:9.8

Severity:Critical

Version: 6.8.9

There is a patch available in v6.9.0 and we strongly recommend you update to this version as soon as possible.