Back to CVE List

CVE-2026-11351

Vulnerability Description

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ShinyStat Analytics

External References

Discussion (0)

Add Comment

No comments yet. Be the first!