What is CVE-2026-11351?
CVE-2026-11351 involves a missing authorization check on a REST API endpoint in the ShinyStat Analytics WordPress plugin before version 1.0.17. This vulnerability allows unauthenticated users to retrieve information about non-published WooCommerce products, such as drafts, pending, or private items. Updating the plugin to version 1.0.17 or later is recommended.
Azərbaycanca: CVE-2026-11351 ShinyStat Analytics WordPress plaginində identifikasiya yoxlanışı olmayan REST API endpoint-i ilə bağlıdır. Bu boşluq autentifikasiya olunmamış istifadəçilərə dərc olunmamış (qaralama, gözləmədə, gizli) WooCommerce məhsul məlumatlarını əldə etməyə imkan verir. Plagini 1.0.17 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What type of data can CVE-2026-11351 potentially expose?
Unauthenticated users can retrieve information about non-published WooCommerce products, such as drafts, pending, or private items.
To which version should users update to address CVE-2026-11351?
Updating the ShinyStat Analytics plugin to version 1.0.17 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.