← WordPress Vulnerabilities
WordPress security by component

ShipTime: Discounted Shipping Rates

ShipTime: Discounted Shipping Rates is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: shiptime-discount-shipping

CVE-2026-59528: ShipTime subscribers can retrieve protected data

ShipTime through 1.1.1 lets a Subscriber retrieve protected data through an undisclosed request path. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.

PublishedJul 27, 2026
Known safe version1.1.5
Safe version
Jul 27, 2026 CVE-2026-59528
ShipTime subscribers can retrieve protected data
ShipTime through 1.1.1 lets a Subscriber retrieve protected data through an undisclosed request path. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
1.1.5
CVE7.5
NVDPending
Apr 08, 2026 CVE-2026-39672
ShipTime: Discounted Shipping Rates: A security weakness
ShipTime: Discounted Shipping Rates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.1.1.
> 1.1.1
CVE5.3
NVDPending