The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44032 | The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-10T20:20:54.656Z
Reserved: 2023-06-22T08:51:03.247Z
Link: CVE-2023-3365
Updated: 2024-08-02T06:55:03.274Z
Status : Modified
Published: 2023-08-07T15:15:11.193
Modified: 2024-11-21T08:17:06.573
Link: CVE-2023-3365
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD