Impact
ShipTime: Discounted Shipping Rates plugin versions 1.1.1 and older allow a subscriber’s sensitive service data to be exposed without authorization. The flaw is a direct read of protected data, resulting in potential disclosure of personally identifiable information and payment details. The weakness aligns with CWE-497, which describes the accidental or intentional reveal of privileged data.
Affected Systems
The vulnerability affects the WordPress ShipTime: Discounted Shipping Rates plugin, provided by ShipTime, for all installations running version 1.1.1 or earlier. Users of these plugin versions on WordPress sites are at risk until the plugin is updated.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, and the EPSS score of < 1% indicates a low exploitation probability. The plugin does not list any active KEV catalog entry. The likely attack vector is inferred from the description; it appears that any user interacting with the plugin through the website could trigger the data extraction, with the required access level being any visitor or, depending on site configuration, an authenticated user. Accordingly, the risk remains significant for exposed subscriber information.
OpenCVE Enrichment