CVE-2026-39602: WordPress Order Tracking plugin <= 3.4.3 - Broken Access Control vulnerability
Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Order Tracking pluginto a version that resolves this vulnerability.Fixed in 3.4.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39602?
CVE-2026-39602 is classified as a Broken Access Control vulnerability affecting WordPress Order Tracking plugin versions up to and including 3.4.3.
How do I fix CVE-2026-39602?
To fix CVE-2026-39602, update the WordPress Order Tracking plugin to version 3.4.4 or later.
What systems are affected by CVE-2026-39602?
CVE-2026-39602 affects the Rustaurius WordPress Order Tracking plugin versions 3.4.3 and earlier.
What types of attacks can CVE-2026-39602 facilitate?
CVE-2026-39602 can facilitate unauthorized access to order tracking information due to incorrectly configured access controls.
Is there a workaround for CVE-2026-39602?
A temporary workaround for CVE-2026-39602 includes disabling the affected plugin until an update is applied.