First published: Mon Mar 20 2023(Updated: )
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Multiple Customer Addresses & Shipping | <21.7 | |
<21.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0865 has a high severity rating due to the potential for unauthorized access to user addresses by any authenticated user.
To fix CVE-2023-0865, update the WooCommerce Multiple Customer Addresses & Shipping plugin to version 21.7 or later.
Any user with an authenticated account on a WordPress site using versions of the WooCommerce Multiple Customer Addresses & Shipping plugin earlier than 21.7 is affected by CVE-2023-0865.
CVE-2023-0865 allows authenticated users to add, update, retrieve, delete, and duplicate addresses that do not belong to them.
No, user authentication is not sufficient as any authenticated user can exploit CVE-2023-0865 unless the plugin is updated.