Security Advisory

CVE-2023-3365

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-08-07 14:31:21
Last updated 2024-10-10 20:20:54
Assigner WPScan
State PUBLISHED

Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment