Fiche vulnérabilité
CVE-2023-3365 : faille élevée multiparcels multiparcels shipping for… (CVSS 8.1)
Description
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment
En bref
- Sévérité
- Élevée (CVSS 8.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 août 2023
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- multiparcels multiparcels shipping for woocommerce