Vulnerabilities / ShipAny WooCommerce: Ship, Label, Tracking
ShipAny WooCommerce: Ship, Label, Tracking vulnerabilities
Advisories WPSec published for ShipAny WooCommerce: Ship, Label, Tracking. Other sources may list more. Its attack surface: ShipAny WooCommerce: Ship, Label, Tracking on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-08 | WPSEC-2026-0638 | ShipAny WooCommerce: Ship, Label, Tracking <= 1.1.112 - Missing Authorization to Authenticated (Subscriber+) Merchant Address Disclosure via 'on_click_update_address' AJAX Action | Medium 4.3 | 1.1.113 |
| 2026-10-08 | WPSEC-2026-0637 | ShipAny WooCommerce: Ship, Label, Tracking <= 1.1.112 - Unauthenticated Sensitive Information Exposure of ShipAny API Token | High 7.5 | 1.1.113 |
License: CC BY 4.0