Cargus

Cargus has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).

The one issue recorded for Cargus has a vendor fix available, so running the current release closes it.

All of these findings were reported by Legion Hunter. Cargus is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Cargus vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-24589

Cargus <= 1.5.8 - Unauthenticated Information Exposure

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Plugin Profile
Latestv1.6.0
2.0(4)
40/100
Last Updated
2026-03-23 (6mo ago)
Active Installs
700+
Downloads
15,306
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2022-07-29 (4y ago)

Cargo delivery. Enables the use of Cargus as a shipping method, management and creation of awbs for orders delivered with Cargus. Important!! The Cargus plugin comes as a rebranding for the existing UrgentCargus plugin. Before installing the Cargus plugin, if the UrgentCargus plugin is present on your site, it must be uninstalled first and only after that you can install, activate and configure the Cargus shipping plugin! Before you are able to use the Cargus plugin you must do the following: – Access urgentcargus.portal. – Click the &#8216;Sign up’ button and fill in the form (you can not use the credentials that the client has for WebExpress). – Confirm your registration by clicking on the link you received by mail (a real email address should be used). – On the urgentcargus.portal page, click on PRODUCTS in the menu, then UrgentOnlineAPI and click &#8216;Subscribe’, then &#8216;Confirm’. – After the Cargus team confirms subscription to the API, the customer receives a confirmation email. – On the urgentcargus.portal page, click on the user name at the top right, then click Profile'. - The two subscription keys are masked by the charactersxxx … xxxand 'Show in the right of each for display. – It is recommended to use Primary key in the Cargus module. You can find the documentation here. The documentation contains all the steps necessary in order to get the required api key, download, install and configure the Cargus plugin. In the documentation you will also find information on how to use and easily customize the plugin using the provided hooks.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C