CVE-2023-2843

CVE-2023-2843: MultiParcels Shipping For WooCommerce < 1.14.15 - Subscribers+ SQLi

Vendor Unknown
Product MultiParcels Shipping For WooCommerce
Published August 7, 2023
Last update October 10, 2024

CVSS base score

What the vulnerability does

01Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

Key dates

02Disclosure timeline

August 7, 2023 CVE published
October 10, 2024 Record updated