Description
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is unauthenticated reflected cross‑site scripting in the MultiParcels Shipping For WooCommerce plugin, allowing an attacker to inject malicious HTML or JavaScript that is reflected back to the browser when a crafted request is made. Such payloads can steal session cookies, deface the site, or redirect users to phishing sites, compromising confidentiality, integrity, and potentially availability if the attacker subverts user trust.

Affected Systems

Vulnerable versions of the WordPress MultiParcels Shipping For WooCommerce plugin up to and including 1.30.36. The plugin is distributed by the vendor multiparcels and is used by WooCommerce‑based e‑commerce sites.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity of this reflected XSS flaw. No EPSS score is published, and the vulnerability is not in the CISA KEV catalog. The flaw can be exploited by sending a crafted URL to any user, without authentication or special permissions, and is typically straightforward for automated tools to leverage. Attackers gain ability to inject scripts that run in victims’ browsers, potentially leading to credential theft or sabotage.

Generated by OpenCVE AI on August 13, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MultiParcels Shipping For WooCommerce plugin to the latest version that addresses the XSS issue, typically version 1.30.37 or newer.
  • If an update is not immediately available, apply a web application firewall rule that blocks payloads containing common XSS attack patterns targeted at the plugin’s URLs.
  • Disable any front‑end features of the plugin that accept user‑supplied input not needed for normal operation, or configure the plugin to sanitize input before reflecting it back to users.

Generated by OpenCVE AI on August 13, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Multiparcels
Multiparcels multiparcels Shipping For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Multiparcels
Multiparcels multiparcels Shipping For Woocommerce
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
Title WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Multiparcels Multiparcels Shipping For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:19:36.757Z

Reserved: 2026-07-27T14:00:43.007Z

Link: CVE-2026-66655

cve-icon Vulnrichment

Updated: 2026-08-13T15:19:32.256Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:17:09.207

Modified: 2026-08-14T19:09:39.140

Link: CVE-2026-66655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T17:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')