Description
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Published: 2026-07-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ShipTime: Discounted Shipping Rates plugin versions 1.1.1 and older allow a subscriber’s sensitive service data to be exposed without authorization. The flaw is a direct read of protected data, resulting in potential disclosure of personally identifiable information and payment details. The weakness aligns with CWE-497, which describes the accidental or intentional reveal of privileged data.

Affected Systems

The vulnerability affects the WordPress ShipTime: Discounted Shipping Rates plugin, provided by ShipTime, for all installations running version 1.1.1 or earlier. Users of these plugin versions on WordPress sites are at risk until the plugin is updated.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate to high severity, and the EPSS score of < 1% indicates a low exploitation probability. The plugin does not list any active KEV catalog entry. The likely attack vector is inferred from the description; it appears that any user interacting with the plugin through the website could trigger the data extraction, with the required access level being any visitor or, depending on site configuration, an authenticated user. Accordingly, the risk remains significant for exposed subscriber information.

Generated by OpenCVE AI on August 4, 2026 at 14:00 UTC.

Remediation

Vendor Solution

Update the WordPress ShipTime: Discounted Shipping Rates Plugin to the latest available version (at least 1.1.5).


OpenCVE Recommended Actions

  • Upgrade the ShipTime: Discounted Shipping Rates plugin to version 1.1.5 or later as the CNA recommends.
  • Reconfigure the plugin and WordPress settings to restrict access to subscriber data to authorized administrators only.
  • Perform a security audit of other WordPress plugins and their data handling to ensure no similar sensitive data exposure exists.

Generated by OpenCVE AI on August 4, 2026 at 14:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Shiptime
Shiptime shiptime: Discounted Shipping Rates
Wordpress
Wordpress wordpress
Vendors & Products Shiptime
Shiptime shiptime: Discounted Shipping Rates
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Title WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Shiptime Shiptime: Discounted Shipping Rates
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:10:08.411Z

Reserved: 2026-07-05T21:27:42.077Z

Link: CVE-2026-59528

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:03.177

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:15:10Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere