PT-2023-24431 · WordPress · Multiparcels Shipping For Woocommerce

Erwan Lr

·

Published

2023-08-07

·

Updated

2024-10-11

·

CVE-2023-3365

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MultiParcels Shipping For WooCommerce WordPress plugin versions prior to 1.14.14
Description The issue concerns a lack of authorization in the deletion of shipments, allowing any authenticated user, such as a subscriber, to delete arbitrary shipments.
Recommendations For versions prior to 1.14.14, update to version 1.14.14 or later to resolve the issue. As a temporary workaround, consider restricting access to shipment deletion functionality to authorized users only until the update can be applied.

Exploit

Fix

Related Identifiers

CVE-2023-3365

Affected Products

Multiparcels Shipping For Woocommerce