Multiparcels

Multiparcels Shipping For Woocommerce

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 09.12.2025 14:52:25
  • Zuletzt bearbeitet 20.01.2026 15:18:20

Missing Authorization vulnerability in multiparcels MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiParcels Shipping For WooCo...

  • EPSS 0.16%
  • Veröffentlicht 15.04.2024 09:15:10
  • Zuletzt bearbeitet 21.11.2024 09:14:27

Cross-Site Request Forgery (CSRF) vulnerability in MultiParcels MultiParcels Shipping For WooCommerce.This issue affects MultiParcels Shipping For WooCommerce: from n/a before 1.16.9.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 21.08.2023 17:15:50
  • Zuletzt bearbeitet 05.05.2025 16:15:47

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 21.08.2023 17:15:48
  • Zuletzt bearbeitet 21.11.2024 08:17:06

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack

Exploit
  • EPSS 0.12%
  • Veröffentlicht 07.08.2023 15:15:11
  • Zuletzt bearbeitet 21.11.2024 08:17:06

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment

Exploit
  • EPSS 0.12%
  • Veröffentlicht 07.08.2023 15:15:11
  • Zuletzt bearbeitet 05.05.2025 16:15:46

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege use...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 07.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:59:24

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection ...