{
 "id": "WPSEC-2026-0637",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0637/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0637/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0637/index.md",
 "title": "ShipAny WooCommerce: Ship, Label, Tracking <= 1.1.112 - Unauthenticated Sensitive Information Exposure of ShipAny API Token",
 "description": "The ShipAny WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 1.0.28 up to, and including, 1.1.112 via the shipping method's settings script data, which is added to front-end pages when a request carries the settings page parameter. This makes it possible for unauthenticated attackers to extract the store's ShipAny API token.",
 "plugin": {
  "slug": "shipany",
  "name": "ShipAny WooCommerce: Ship, Label, Tracking",
  "full_name": "ShipAny WooCommerce: Ship, Label, Tracking",
  "wordpress_org": "https://wordpress.org/plugins/shipany/",
  "advisories_url": "https://wpsec.com/vuln/plugin/shipany/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/shipany"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.0.28",
    "from_inclusive": true,
    "to": "1.1.113",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.0.28 before 1.1.113"
  ]
 },
 "introduced_in": "1.0.28",
 "fixed_in": "1.1.113",
 "remediation": "Update to 1.1.113 or later.",
 "fix_released": "2026-10-07T10:01:44+00:00",
 "published": "2026-10-08T10:46:37+00:00",
 "updated": "2026-10-07T19:15:22.889067+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0637/",
  "https://plugins.svn.wordpress.org/shipany/tags/1.1.113/",
  "https://wordpress.org/plugins/shipany/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/shipany",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}