CVE Published: 07/08/2023 |
CVE Updated: 10/10/2024 |
CVE Year: 2023 Source: WPScan |
Vendor: Unknown |
Product: MultiParcels Shipping For WooCommerce Status : PUBLISHED
CVE-2023-3365 Description
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment