PT-2023-24431 · WordPress · Multiparcels Shipping For Woocommerce
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MultiParcels Shipping For WooCommerce WordPress plugin versions prior to 1.14.14
Description
The issue concerns a lack of authorization in the deletion of shipments, allowing any authenticated user, such as a subscriber, to delete arbitrary shipments.
Recommendations
For versions prior to 1.14.14, update to version 1.14.14 or later to resolve the issue. As a temporary workaround, consider restricting access to shipment deletion functionality to authorized users only until the update can be applied.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Multiparcels Shipping For Woocommerce