CVE-2023-3365

CVE-2023-3365: MultiParcels Shipping For WooCommerce < 1.14.14 - Subscriber+ Arbitrary Shipment Deletion

Vendor Unknown
Product MultiParcels Shipping For WooCommerce
Published August 7, 2023
Last update October 10, 2024

CVSS base score

What the vulnerability does

01Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment

Key dates

02Disclosure timeline

August 7, 2023 CVE published
October 10, 2024 Record updated