← Retour à la recherche de CVE

CVE-2026-11351

ShinyStat Analytics

Description

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.

CVSS 5.3EPSS 0.20600000000000002%Risque 0.54
Voir la source
Publication
2026-07-29 07:16:40
Versions concernées
<1.0.17
Type
Application web
Dernière modification
2026-07-30 14:16:31
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N