The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2023-03-20 09:15
Updated : 2023-03-21 04:51
NVD link : CVE-2023-0865
Mitre link : CVE-2023-0865
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
No product.