CVE Published: 07/08/2023 |
CVE Updated: 10/10/2024 |
CVE Year: 2023 Source: WPScan |
Vendor: Unknown |
Product: MultiParcels Shipping For WooCommerce Status : PUBLISHED
CVE-2023-2843 Description
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.