Shelf Planner [shelf-planner] <= 2.7.0 (unfixed)
unknown
[en] The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey a...
- Affected:
- up to 2.7.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 11, 2025
CVE-2025-11894 on NVD →
Shelf Planner [shelf-planner] <= 2.7.0 (unfixed)
unknown
[en] The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.0 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
- Affected:
- up to 2.7.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 11, 2025
CVE-2025-11891 on NVD →
Shelf Planner <= 2.8.1 - Missing Authorization to Unauthenticated Settings Update
medium
The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and Li...
- CVSS:
- 5.3
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Nov 10, 2025
CVE-2025-11894 on NVD →
Shelf Planner <= 2.8.1 - Unauthenticated Information Exposure via Log Files
medium
The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files.
- CVSS:
- 5.3
- Affected:
- up to 2.8.1
- Fixed in:
- 2.8.2
- Disclosed:
- Nov 10, 2025
CVE-2025-11891 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database