SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-11351

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The ShinyStat Analytics plugin for WordPress prior to version 1.0.17 lacks proper authorization checks on a REST API endpoint, enabling unauthenticated users to access sensitive information about non-published WooCommerce products, including drafts and private items. This vulnerability poses a risk of data exposure, making it crucial for WordPress site administrators using this plugin to prioritize updates to mitigate potential information leaks.

CVE
CVE-2026-11351
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.