WordPress security by component
ShipTime: Discounted Shipping Rates
Plugin description
ShipTime: Discounted Shipping Rates is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
shiptime-discount-shippingLatest vulnerability
CVE-2026-59528: ShipTime subscribers can retrieve protected data
ShipTime through 1.1.1 lets a Subscriber retrieve protected data through an undisclosed request path. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-59528
ShipTime subscribers can retrieve protected data
ShipTime through 1.1.1 lets a Subscriber retrieve protected data through an undisclosed request path. The Patchstack CNA record does not disclose the endpoint, action, parameter, function or data fields returned, so the sensitivity and practical scope of the disclosure remain unknown.
|
1.1.5 |
CVE7.5
NVDPending
|
| Apr 08, 2026 |
CVE-2026-39672
ShipTime: Discounted Shipping Rates: A security weakness
ShipTime: Discounted Shipping Rates is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.1.1.
|
> 1.1.1 |
CVE5.3
NVDPending
|