CVE-2023-3954

CVE-2023-3954: MultiParcels Shipping For WooCommerce 1.15.2-1.15.3 - Reflected XSS

Vendor Unknown
Product MultiParcels Shipping For WooCommerce
Published August 21, 2023
Last update May 5, 2025

CVSS base score

What the vulnerability does

01Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Key dates

02Disclosure timeline

August 21, 2023 CVE published
May 5, 2025 Record updated