Executive brief
The ShipTime plugin for WordPress, which provides discounted shipping rates for e-commerce sites, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions that should be restricted to administrators or specific users. While the impact is considered moderate, it could allow attackers to interfere with shipping configurations or plugin settings without permission.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the ShipTime: Discounted Shipping Rates plugin for WordPress. The issue stems from incorrectly configured access control security levels or missing authorization checks in plugin functions. An unauthenticated remote attacker can exploit this flaw to execute actions that should require higher privileges. The vulnerability is resolved in version 1.1.5. CVSS analysis indicates a base score of 5.3, primarily impacting integrity.
Affected products
- ShipTime ShipTime: Discounted Shipping Rates <= 1.1.4
Timeline
- 2026-01-20: other: Reported by Legion Hunter to Patchstack
- 2026-02-19: disclosed: Initial disclosure by Patchstack
- 2026-02-19: patched: Version 1.1.5 released to address the issue
- 2026-04-08: advisory: CVE published