Security
All publicly reported vulnerabilities are fixed.
Last reviewed: 2026-08-12
This page is the vendor record for every publicly reported security issue in the plugin. Each entry links to the external advisory it came from, so nothing here has to be taken on trust.
| Identifier | Type | Affected versions | Fixed in | Reported | Severity | Source |
|---|---|---|---|---|---|---|
| CVE-2026-9253 | Stored cross-site scripting (unauthenticated) | <= 10.5.97 | 10.6.1 | 2026-07-09 | High (7.2) | The NVD record states the affected range but carries no explicit remediation line naming the fixed version. This advisory is also absent from WPScan and Patchstack at the time of review. |
| No CVE assigned | Missing authorization / broken access control | < 10.3.0 | 10.3.0 | 2026-03-23 | Medium (5.3) | |
| CVE-2024-32510 | Reflected cross-site scripting | <= 10.1.75 | 10.1.76 | 2024-04-15 | Medium (6.1) | Scored 6.1 by WPScan and 7.1 by Patchstack. We list the lower-bound score and link both. |
| No CVE assigned | Broken access control | <= 10.1.76 | 10.1.77 | 2024-04-15 | Not scored | |
| No CVE assigned | SQL injection (authenticated, Contributor+) | <= 10.1.75 | 10.1.76 | 2024-03-28 | Not scored | |
| No CVE assigned | Upload directory traversal | < 9.660 | 9.660 | 2019-02-14 | Not scored | |
| No CVE assigned | Arbitrary file upload and delete | < 9.644 | 9.644 | 2019-02-14 | Not scored |
Where public databases disagree or are incomplete, the difference is stated in the row.
CVE-2026-9253 is an unauthenticated stored cross-site scripting issue in the customer information submitted with an order. It affects versions <= 10.5.97 and was fixed in 10.6.1. The 10.6.1 changelog records it as: "Security: fixed unauthenticated stored XSS via submitted customer information in order records."
The NVD record states the affected range but carries no explicit remediation line naming the fixed version. This advisory is also absent from WPScan and Patchstack at the time of review.
Until those records name the fixed version, this page is the vendor’s authoritative statement on it.
Contact: security@loopus.tech
Report security issues privately to the address above. Please include the affected version, reproduction steps, and the impact you observed.
The plugin and its official distribution channels.
Out of scope: raw automated scanner output with no reproduction, and social engineering of our team or customers.
Check your installed version in the WordPress admin under Plugins, or in the Cost Estimation menu.
Update from the WordPress Plugins screen. Running the latest release is the only supported configuration.