Vulnerability CVE-2023-3365


Published: 2023-08-07

Description:
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment

Type:

CWE-862

(Missing Authorization)

 References:
https://wpscan.com/vulnerability/21ce5baa-8085-4053-8d8b-f7d3e2ae70c1

Copyright 2026, cxsecurity.com

 

Back to Top