
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25401 is a Missing Authorization vulnerability in the WPCargo Track & Trace WordPress plugin developed by Arni Cinco. The flaw allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, potentially exposing sensitive shipment tracking data. It affects all versions of the plugin through 8.0.2. The vulnerability was published on March 25, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to restricted functionality or data. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability is categorized under broken access control, where certain plugin endpoints or AJAX actions do not enforce capability checks, allowing unauthorized access to protected resources (Feedly, Patchstack).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can read sensitive data managed by the plugin — such as shipment tracking records, order details, or customer information — without authorization. The scope is unchanged, limiting direct impact to the affected WordPress installation, but exposed data could be leveraged for further social engineering or targeted attacks against customers. There is no evidence of integrity modification or service disruption as part of this vulnerability's direct impact (Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2026-25401 as of the available data. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Feedly).
Users should update the WPCargo Track & Trace plugin to a version beyond 8.0.2 that includes the access control fix. If an updated version is not yet available, site administrators should consider temporarily deactivating the plugin until a patch is released. Additionally, implementing a Web Application Firewall (WAF) — such as those offered by Wordfence or Patchstack — can help block unauthorized access attempts targeting vulnerable plugin endpoints (Patchstack, Wordfence).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of March 23–29, 2026, indicating routine tracking by the WordPress security community. Patchstack, which was the assigning CNA, published the advisory and flagged it as a broken access control issue. No significant social media discussion or notable researcher commentary beyond standard disclosure has been observed (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."