Impact
Missing authorisation allows attackers to exploit incorrect access control levels. The vulnerability could enable unauthorized users to access or manipulate the plugin’s shipping configuration, potentially altering shipping options, fees, or other critical settings within a WooCommerce store.
Affected Systems
MultiParcels Shipping For WooCommerce plugin version 1.30.12 and earlier, distributed by the vendor multiparcels, is affected.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low likelihood of active exploitation. The vulnerability is not listed in the CISA KEV catalogue. Based on the description, the likely attack vector involves interacting with the plugin’s web interfaces from within a compromised or publicly accessible WordPress installation, using the exposed endpoints to bypass role restrictions.
OpenCVE Enrichment