PatchSiren

shiptime CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM shiptime CVE published 2026-04-08

CVE-2026-39672

The ShipTime: Discounted Shipping Rates plugin for WordPress has a Missing Authorization vulnerability, allowing attackers to exploit incorrectly configured access control security levels. This issue affects versions from n/a through <= 1.1.1. The vulnerability has a CVSS score of 5.3 and is considered Medium priority. Users of the plugin should verify their installation and update to a patched version if [truncated]