CVE-2025-62995
- EPSS 0.04%
- Veröffentlicht 09.12.2025 14:52:25
- Zuletzt bearbeitet 20.01.2026 15:18:20
Missing Authorization vulnerability in multiparcels MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiParcels Shipping For WooCo...
CVE-2024-32095
- EPSS 0.16%
- Veröffentlicht 15.04.2024 09:15:10
- Zuletzt bearbeitet 21.11.2024 09:14:27
Cross-Site Request Forgery (CSRF) vulnerability in MultiParcels MultiParcels Shipping For WooCommerce.This issue affects MultiParcels Shipping For WooCommerce: from n/a before 1.16.9.
CVE-2023-3954
- EPSS 0.13%
- Veröffentlicht 21.08.2023 17:15:50
- Zuletzt bearbeitet 05.05.2025 16:15:47
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such...
CVE-2023-3366
- EPSS 0.07%
- Veröffentlicht 21.08.2023 17:15:48
- Zuletzt bearbeitet 21.11.2024 08:17:06
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack
CVE-2023-3365
- EPSS 0.12%
- Veröffentlicht 07.08.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 08:17:06
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment
CVE-2023-3671
- EPSS 0.12%
- Veröffentlicht 07.08.2023 15:15:11
- Zuletzt bearbeitet 05.05.2025 16:15:46
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege use...
CVE-2023-2843
- EPSS 0.33%
- Veröffentlicht 07.08.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 07:59:24
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection ...