Multiparcels
multiparcels
5 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Multiparcels 1Multiparcels Shipping For Woocommerce Jun 17, 2026 Aug 21, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used aga...Show more |
1Multiparcels 1Multiparcels Shipping For Woocommerce Jun 17, 2026 Aug 21, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete arbitrary shipment via a CSRF attack |
1Multiparcels 1Multiparcels Shipping For Woocommerce Jun 17, 2026 Aug 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be u...Show more |
1Multiparcels 1Multiparcels Shipping For Woocommerce Jun 17, 2026 Aug 7, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber to delete arbitrary shipment |
1Multiparcels 1Multiparcels Shipping For Woocommerce Jun 17, 2026 Aug 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscrib...Show more |