CVE-2026-11351
Received Received - Intake

Unauthenticated Access to WooCommerce Product Data in ShinyStat Analytics

Vulnerability report for CVE-2026-11351, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: WPScan

Description

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
shinystat analytics to 1.0.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the ShinyStat Analytics WordPress plugin before version 1.0.17. It allows unauthenticated users to access sensitive information about non-published WooCommerce products, such as draft, pending, or private items. The plugin exposes a REST API endpoint that does not require authentication, enabling attackers to retrieve details like titles, descriptions, pricing, images, and categories.

Detection Guidance

Check if the ShinyStat Analytics WordPress plugin version is below 1.0.17. Test the exposed REST API endpoint by sending unauthenticated requests to shinystat/v1/product/<id> for various product IDs to see if sensitive data like titles, descriptions, or pricing is returned.

Impact Analysis

Attackers could exploit this to gather confidential product details before they are officially published. This may lead to competitive disadvantages, loss of revenue, or reputational damage if sensitive pricing or product information is exposed prematurely.

Compliance Impact

This vulnerability could potentially violate GDPR and HIPAA compliance by exposing sensitive product data, including pricing and descriptions, which may contain personally identifiable information (PII). Unauthorized access to non-published WooCommerce products risks breaching data confidentiality requirements under these regulations.

Mitigation Strategies

Update the ShinyStat Analytics plugin to version 1.0.17 or later immediately. If an update is not available, consider disabling the plugin temporarily until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11351. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart