CVE-2023-2843: Multiparcels Shipping For Woocommerce
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.
Affected products
- Multiparcels Multiparcels Shipping For Woocommerce: before 1.14.15 (fixed in 1.14.15)
Published 2023-08-07. Last modified 2026-06-17.