Loading...

Security

Current secure version: 10.6.4

All publicly reported vulnerabilities are fixed.

Last reviewed: 2026-08-12

This page is the vendor record for every publicly reported security issue in the plugin. Each entry links to the external advisory it came from, so nothing here has to be taken on trust.

Reported vulnerabilities

IdentifierTypeAffected versionsFixed inReportedSeveritySource
CVE-2026-9253Stored cross-site scripting (unauthenticated)<= 10.5.9710.6.12026-07-09High (7.2)

The NVD record states the affected range but carries no explicit remediation line naming the fixed version. This advisory is also absent from WPScan and Patchstack at the time of review.

No CVE assignedMissing authorization / broken access control< 10.3.010.3.02026-03-23Medium (5.3)
CVE-2024-32510Reflected cross-site scripting<= 10.1.7510.1.762024-04-15Medium (6.1)

Scored 6.1 by WPScan and 7.1 by Patchstack. We list the lower-bound score and link both.

No CVE assignedBroken access control<= 10.1.7610.1.772024-04-15Not scored
No CVE assignedSQL injection (authenticated, Contributor+)<= 10.1.7510.1.762024-03-28Not scored
No CVE assignedUpload directory traversal< 9.6609.6602019-02-14Not scored
No CVE assignedArbitrary file upload and delete< 9.6449.6442019-02-14Not scored

Where public databases disagree or are incomplete, the difference is stated in the row.

About CVE-2026-9253

CVE-2026-9253 is an unauthenticated stored cross-site scripting issue in the customer information submitted with an order. It affects versions <= 10.5.97 and was fixed in 10.6.1. The 10.6.1 changelog records it as: "Security: fixed unauthenticated stored XSS via submitted customer information in order records."

The NVD record states the affected range but carries no explicit remediation line naming the fixed version. This advisory is also absent from WPScan and Patchstack at the time of review.

Until those records name the fixed version, this page is the vendor’s authoritative statement on it.

Reporting a vulnerability

Contact: security@loopus.tech

Report security issues privately to the address above. Please include the affected version, reproduction steps, and the impact you observed.

  • We acknowledge reports within 3 business days.
  • After triage we share a fix timeline with the reporter.
  • Reporters are credited on this page unless they prefer otherwise.
  • Good-faith research is welcome; we will not pursue legal action against it.

Scope

The plugin and its official distribution channels.

Out of scope: raw automated scanner output with no reproduction, and social engineering of our team or customers.

Staying current

Check your installed version in the WordPress admin under Plugins, or in the Cost Estimation menu.

Update from the WordPress Plugins screen. Running the latest release is the only supported configuration.