Security Advisory

CVE-2023-3366

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-08-21 12:29:50
Last updated 2024-10-03 20:02:05
Assigner WPScan
State PUBLISHED

Description

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack