Sensitive Data Exposure in ShipTime Discounted Shipping Plugin by WordPress
CVE-2026-59528
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 July 2026
What is CVE-2026-59528?
The ShipTime: Discounted Shipping Rates plugin for WordPress contains a vulnerability that exposes sensitive subscriber data in versions up to 1.1.1. This flaw allows unauthorized access to sensitive user information, posing a risk to data privacy and security. Users of affected versions are advised to update their plugins promptly to mitigate the risk of data breaches.
Affected Version(s)
ShipTime: Discounted Shipping Rates <= 1.1.1