What the vulnerability does
01Description
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.5.
Explanation of Vulnerability in Simple Terms
The WooCommerce Ship to Multiple Addresses plugin through version 3.8.5 does not properly check user permissions before allowing modifications to shipping addresses. A logged-in user with low privileges can alter shipping data they should not have access to. Update to a version newer than 3.8.5.
What an attacker can do
Modify shipping addresses and related data without proper authorization.
Potential impact on your site
Customers or low-privilege users could alter shipping information for orders they don't own.
Conditions required to exploit
Attacker must be logged in as a low-privilege user (e.g., customer account).
Key dates
External resources
Related vulnerabilities