PT-2023-24431 · WordPress · Multiparcels Shipping For Woocommerce

·

CVE-2023-3365

·

Publicado

2023-08-07

·

Atualizado

2024-10-11

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MultiParcels Shipping For WooCommerce WordPress plugin versions prior to 1.14.14
Description The issue concerns a lack of authorization in the deletion of shipments, allowing any authenticated user, such as a subscriber, to delete arbitrary shipments.
Recommendations For versions prior to 1.14.14, update to version 1.14.14 or later to resolve the issue. As a temporary workaround, consider restricting access to shipment deletion functionality to authorized users only until the update can be applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-3365

Produtos afetados

Multiparcels Shipping For Woocommerce