MEDIUM
shiptime
CVE published 2026-04-08
CVE-2026-39672
The ShipTime: Discounted Shipping Rates plugin for WordPress has a Missing Authorization vulnerability, allowing attackers to exploit incorrectly configured access control security levels. This issue affects versions from n/a through <= 1.1.1. The vulnerability has a CVSS score of 5.3 and is considered Medium priority. Users of the plugin should verify their installation and update to a patched version if [truncated]