PatchSiren

shiptime CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH shiptime CVE published 2026-07-27

CVE-2026-59528

The CVE record for CVE-2026-59528 was published on 2026-07-27T15:17:03.177Z and has not been modified since then. This CVE is associated with a Subscriber Sensitive Data Exposure vulnerability in ShipTime: Discounted Shipping Rates plugin versions <= 1.1.1. The vulnerability has a CVSS score of 7.5 and a severity of HIGH. Users of affected versions should review and apply patches or updates provided by th [truncated]

MEDIUM shiptime CVE published 2026-04-08

CVE-2026-39672

The ShipTime: Discounted Shipping Rates plugin for WordPress has a Missing Authorization vulnerability, allowing attackers to exploit incorrectly configured access control security levels. This issue affects versions from n/a through <= 1.1.1. The vulnerability has a CVSS score of 5.3 and is considered Medium priority. Users of the plugin should verify their installation and update to a patched version if [truncated]