CVE-2023-3365

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:multiparcels:multiparcels_shipping_for_woocommerce:*:*:*:*:*:wordpress:*:*

Information

Published : 2023-08-07 15:15

Updated : 2023-08-09 17:53


NVD link : CVE-2023-3365

Mitre link : CVE-2023-3365


JSON object : View

Products Affected

multiparcels

  • multiparcels_shipping_for_woocommerce
CWE
CWE-862

Missing Authorization