Junglewise Threat Intelligence

CVE-2026-59528: ShipTime Discounted Shipping Rates sensitive data exposure

CVE-2026-59528 · Severity: high · CVSS 7.5 · Published 2026-07-27

Executive brief

The ShipTime plugin for WordPress, which provides discounted shipping rates for e-commerce sites, contains a security flaw that exposes sensitive information. An unauthorized person could access data that should be private, potentially leading to the exposure of customer or system details. This could compromise user privacy and provide attackers with information needed for further attacks.

Technical details

The ShipTime: Discounted Shipping Rates plugin for WordPress (versions <= 1.1.1) is vulnerable to sensitive data exposure (CWE-497). The vulnerability allows an attacker to access sensitive system or user information that should be restricted. While the advisory mentions 'Subscriber' under required privileges in some contexts, the CVSS vector (PR:N) suggests the data may be accessible without authentication or via low-privileged accounts. This exposure can be leveraged by attackers to gain insights into the system configuration or user data. The issue is resolved in version 1.1.5.

Affected products

  • ShipTime ShipTime: Discounted Shipping Rates <= 1.1.1

Timeline

  • 2026-02-11: other: Reported by VuNBT
  • 2026-07-23: disclosed: Vulnerability details published by Patchstack
  • 2026-07-27: advisory: NVD publication date

References

Related threats