ShipAny WooCommerce: Ship, Label, Tracking <= 1.1.112 - Unauthenticated Sensitive Information Exposure of ShipAny API Token

High 7.5 CWE-200Fixed in 1.1.113
ID
WPSEC-2026-0637
Plugin
ShipAny WooCommerce: Ship, Label, Tracking (shipany)
Affected
from 1.0.28 before 1.1.113
Remediation
Update to 1.1.113 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-200
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
ShipAny WooCommerce: Ship, Label, Tracking on WPSec AttackSurface
Fix released
Published

Description

The ShipAny WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.0.28 up to, and including, 1.1.112 via the shipping method's settings script data, which is added to front-end pages when a request carries the settings page parameter. This makes it possible for unauthenticated attackers to extract the store's ShipAny API token.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0