Description
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is unauthenticated reflected cross‑site scripting in the MultiParcels Shipping For WooCommerce plugin, allowing an attacker to inject malicious HTML or JavaScript that is reflected back to the browser when a crafted request is made. Such payloads can steal session cookies, deface the site, or redirect users to phishing sites, compromising confidentiality, integrity, and potentially availability if the attacker subverts user trust.

Affected Systems

Vulnerable versions of the WordPress MultiParcels Shipping For WooCommerce plugin up to and including 1.30.36. The plugin is distributed by the vendor multiparcels and is used by WooCommerce‑based e‑commerce sites.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity of this reflected XSS flaw. No EPSS score is published, and the vulnerability is not in the CISA KEV catalog. The flaw can be exploited by sending a crafted URL to any user, without authentication or special permissions, and is typically straightforward for automated tools to leverage. Attackers gain ability to inject scripts that run in victims’ browsers, potentially leading to credential theft or sabotage.

Generated by OpenCVE AI on August 13, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MultiParcels Shipping For WooCommerce plugin to the latest version that addresses the XSS issue, typically version 1.30.37 or newer.
  • If an update is not immediately available, apply a web application firewall rule that blocks payloads containing common XSS attack patterns targeted at the plugin’s URLs.
  • Disable any front‑end features of the plugin that accept user‑supplied input not needed for normal operation, or configure the plugin to sanitize input before reflecting it back to users.

Generated by OpenCVE AI on August 13, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
Title WordPress MultiParcels Shipping For WooCommerce plugin <= 1.30.36 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:19:36.757Z

Reserved: 2026-07-27T14:00:43.007Z

Link: CVE-2026-66655

cve-icon Vulnrichment

Updated: 2026-08-13T15:19:32.256Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:09.207

Modified: 2026-08-13T16:18:46.040

Link: CVE-2026-66655

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')