Impact
The ShinyStat Analytics WordPress plugin, versions prior to 1.0.17, contains a REST API endpoint that performs no authorization checks, allowing anyone to retrieve details of WooCommerce products that are in draft, pending, or private states. This represents an information disclosure vulnerability (CWE-200), whereby confidential product data can be exposed to unauthenticated users.
Affected Systems
Any WordPress site running the ShinyStat Analytics plugin before version 1.0.17 is affected. Sites that use WooCommerce for product management are particularly vulnerable because the exposed data pertains to non-public products configured within WooCommerce. No specific plugin version list is provided beyond the cutoff of 1.0.17.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of < 1% suggests a low likelihood of real‑world exploitation at present. Because the vulnerable endpoint is publicly accessible without credentials, an attacker could simply issue a HTTP request to recover non‑published product information, but the impact remains limited to disclosure of internal data rather than full system compromise. The vulnerability is not listed in the CISA KEV catalog, further indicating that no widespread active exploits have been reported.
OpenCVE Enrichment