What the vulnerability does
01Description
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.
Explanation of Vulnerability in Simple Terms
The WooCommerce Ship to Multiple Addresses plugin through version 3.8.9 lacks proper authorization checks on certain operations. A logged-in user with low privileges can modify shipping data or settings they should not have access to. The vulnerability requires an active user account but no special interaction from the victim.
What an attacker can do
Modify shipping addresses or settings belonging to other users or orders.
Potential impact on your site
Customer shipping data could be altered by unauthorized users, affecting order fulfillment and customer trust.
Conditions required to exploit
Attacker must have a valid user account on the site with at least low-level privileges.
Key dates
External resources
Related vulnerabilities