Vulnerabilities / ShipAny WooCommerce: Ship, Label, Tracking / WPSEC-2026-0637
ShipAny WooCommerce: Ship, Label, Tracking <= 1.1.112 - Unauthenticated Sensitive Information Exposure of ShipAny API Token
High 7.5
CWE-200Fixed in 1.1.113
- ID
- WPSEC-2026-0637
- Plugin
- ShipAny WooCommerce: Ship, Label, Tracking (shipany)
- Affected
- from 1.0.28 before 1.1.113
- Remediation
- Update to 1.1.113 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- ShipAny WooCommerce: Ship, Label, Tracking on WPSec AttackSurface
- Fix released
- Published
Description
The ShipAny WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.0.28 up to, and including, 1.1.112 via the shipping method's settings script data, which is added to front-end pages when a request carries the settings page parameter. This makes it possible for unauthenticated attackers to extract the store's ShipAny API token.
References
- https://wpsec.com/vuln/WPSEC-2026-0637/
- https://plugins.svn.wordpress.org/shipany/tags/1.1.113/
- https://wordpress.org/plugins/shipany/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS