MultiParcels Shipping For WooCommerce < 1.14.14 - Subscriber+ Arbitrary Shipment Deletion
CVE-2023-3365
8.1HIGH
What is CVE-2023-3365?
The MultiParcels Shipping For WooCommerce plugin before version 1.14.14 is susceptible to an authorization vulnerability that allows any authenticated user, including subscribers, to delete arbitrary shipments. This flaw can lead to unauthorized removal of shipment data, potentially affecting ecommerce operations and user trust.
Affected Version(s)
MultiParcels Shipping For WooCommerce 0 < 1.14.14