Back to overview

CVE-2026-11351

Description
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.

Metadata

CVE ID
CVE-2026-11351
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-05 11:12 UTC
Published
2026-07-29 06:00 UTC
Last updated
2026-07-29 06:00 UTC
Vendor / Product
Unknown / ShinyStat Analytics
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown ShinyStat Analytics 1.0.12 < 1.0.17
Weakness (CWE)
CWESourceDescription
cna CWE-200 Information Exposure
Back to overview