ZeroHour

CVE-2023-3365

PoC
CVSS 3.1
8.1 high
EPSS
<1%p53
Published
()
Modified
Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment

Vendors
multiparcels
Products
multiparcels shipping for woocommerce
Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.