The WooCommerce Multiple Customer Addresses & Shipping...
High severity
Unreviewed
Published
Mar 20, 2023
to the GitHub Advisory Database
•
Updated Mar 31, 2023
Description
Published by the National Vulnerability Database
Mar 20, 2023
Published to the GitHub Advisory Database
Mar 20, 2023
Last updated
Mar 31, 2023
The WooCommerce Multiple Customer Addresses & Shipping WordPress plugin before 21.7 does not ensure that the address to add/update/retrieve/delete and duplicate belong to the user making the request, or is from a high privilege users, allowing any authenticated users, such as subscriber to add/update/duplicate/delete as well as retrieve addresses of other users.
References