CVE-2026-11351: Unknown Shinystat Analytics

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenticated users to retrieve information about non-published (e.g. draft, pending or private) WooCommerce products.

Affected products

  • Unknown Shinystat Analytics: from 1.0.12, before 1.0.17 (fixed in 1.0.17)

Published 2026-07-29. Last modified 2026-07-30.