8.1
CVE-2023-3365
- EPSS 0.12%
- Veröffentlicht 07.08.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 08:17:06
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
MultiParcels Shipping For WooCommerce <= 1.14.13 - Missing Authorization via get_history
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment
Mögliche Gegenmaßnahme
MultiParcels Shipping For WooCommerce: Update to version 1.14.14, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
MultiParcels Shipping For WooCommerce
Version
*-1.14.13
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Multiparcels ≫ Multiparcels Shipping For Woocommerce SwPlatformwordpress Version < 1.14.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.309 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|