CVE-2023-3366

CVE-2023-3366: MultiParcels Shipping For WooCommerce < 1.15.2 - Arbitrary Shipment Deletion via CSRF

Vendor Unknown
Product MultiParcels Shipping For WooCommerce
Published August 21, 2023
Last update October 3, 2024

CVSS base score

—

What the vulnerability does

01Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

Key dates

02Disclosure timeline

August 21, 2023 CVE published
October 3, 2024 Record updated