CVE-2023-2843: Multiparcels Shipping For Woocommerce

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.

Affected products

  • Multiparcels Multiparcels Shipping For Woocommerce: before 1.14.15 (fixed in 1.14.15)

Published 2023-08-07. Last modified 2026-06-17.