CVE-2023-3366

CVE-2023-3366: MultiParcels Shipping For WooCommerce < 1.15.2 - Arbitrary Shipment Deletion via CSRF

Vendor Unknown
Product MultiParcels Shipping For WooCommerce
Published August 21, 2023
Last update October 3, 2024

CVSS base score

What the vulnerability does

01Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

Key dates

02Disclosure timeline

August 21, 2023 CVE published
October 3, 2024 Record updated