Beveiligingsadvies

CVE-2023-2843

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-08-07 14:31:25
Laatst bijgewerkt 2024-10-10 19:37:32
Toegewezen door WPScan
CVSS-score 8.8
Status PUBLISHED

Beschrijving

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.