CVE-2026-11351
Description
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | ShinyStat Analytics | — | 1.0.12 < 1.0.17 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-200 Information Exposure |