CVE-2026-59528
ShipTime · Discounted Shipping Rates
The ShipTime: Discounted Shipping Rates WordPress plugin is vulnerable to sensitive data exposure due to a lack of proper authorization checks.
Executive summary
A critical sensitive data exposure vulnerability in the ShipTime: Discounted Shipping Rates plugin allows unauthenticated attackers to access restricted information.
Vulnerability
This vulnerability is a sensitive data exposure flaw (CWE-497) caused by the failure to restrict access to internal system information. It allows unauthenticated users to perform unauthorized queries that retrieve sensitive data, as indicated by the network attack vector and no required privileges in the CVSS vector.
Business impact
The exposure of sensitive system information can lead to unauthorized access to proprietary shipping data or configuration details, potentially facilitating further attacks. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to the confidentiality of customer and business information managed through the plugin.
Remediation
Immediate Action: Update the WordPress ShipTime: Discounted Shipping Rates plugin to version 1.1.5 or later to resolve the underlying access control flaw.
Proactive Monitoring: Review web server access logs for unusual patterns of requests directed at the plugin endpoints and monitor for unexpected data export activities.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter out suspicious requests targeting the plugin's sensitive functions until the update is successfully applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high CVSS score and the nature of the data exposure necessitate an immediate update to the patched version. Organizations should prioritize this update to prevent unauthorized access to sensitive business information and maintain the integrity of their shipping management platform.