ShipTime: Discount Shipping
ShipTime: Discount Shipping has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 2 are fixed as of August 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10. 2026 was the busiest year with 2 disclosures.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (50%). Other recurring categories include Missing Authorization.
Every one of the 2 issues recorded for ShipTime: Discount Shipping has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. ShipTime: Discount Shipping is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-39672ShipTime: Discounted Shipping Rates <= 1.1.4 - Missing Authorization
Read the full analysisVulnerability Records

ShipTime: Discount Shipping
Author
shiptime
woocommerceThis plugin provides real-time discounted shipping rates from ShipTime. You can enable real-time rates at check-out and your customers can select from the top national couriers and compare cost, time in transit and services. Your orders will sync to your ShipTime account where automation takes over with autoboxing; intelligently packing your items using boxes in your box library. Pick-ups can then be scheduled and labels printed in minutes. Your shipment creation status will be updated in WooCommerce as fulfilled and your customer can be notified of the shipment status and delivery via ShipTime’s automated notification process. You can also customize notifications using ShipTime’s Branded Tracking feature.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C