CVE-2023-32799: WordPress WooCommerce Ship to Multiple Addresses Plugin <= 3.8.3 is vulnerable to Insecure Direct Object References (IDOR)
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32799?
CVE-2023-32799 has been classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2023-32799?
To remediate CVE-2023-32799, update the WooCommerce Shipping Multiple Addresses plugin to version 3.8.4 or later.
What types of systems are affected by CVE-2023-32799?
CVE-2023-32799 affects all versions of the WooCommerce Shipping Multiple Addresses plugin up to and including version 3.8.3.
What exploitation risk does CVE-2023-32799 pose?
CVE-2023-32799 allows attackers to bypass authorization controls, potentially accessing sensitive user data.
When was CVE-2023-32799 reported?
CVE-2023-32799 was officially reported in 2023, highlighting a critical vulnerability in the WooCommerce Shipping Multiple Addresses plugin.