BD Courier Order Ratio Checker

BD Courier Order Ratio Checker has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for BD Courier Order Ratio Checker has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by Nabil Irawan. BD Courier Order Ratio Checker is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all BD Courier Order Ratio Checker vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2026-22481

BD Courier Order Ratio Checker <= 2.0.1 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
BD Courier Order Ratio Checker banner
Latestv3.0.3

BD Courier Order Ratio Checker

Rasedul Haque Rumi

Author

Rasedul Haque Rumi

5.0(3)
100/100
Last Updated
2026-07-09 (2mo ago)
Active Installs
2,000+
Downloads
11,967
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2024-10-06 (2y ago)

Order Ratio Checker integrates with BD Courier’s API to display customer order ratios in a simple and user-friendly way. The plugin offers easy setup, making it accessible to users who want to track order statistics without any complex configuration. Note: You need to register for free on BD Courier’s website to access the API. Once registered, you can start using the plugin with the API token provided. Features: Fetch and display order ratios (Total, Success, Cancel) using BD Courier’s API. WooCommerce integration to display courier information on the order page. Customizable search form with AJAX-based submission. Admin settings for entering API token after registration. License This plugin is licensed under the GPLv2 or later.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C