plugin

Wc Multishipping Vulnerabilities

8 known security issues reported for the Wc Multishipping WordPress plugin. Most recent disclosed Jun 10, 2026.

3 medium

Running Wc Multishipping on your site? Check whether your installed version is affected.

Scan your site free

WCMultiShipping — Mondial Relay, Inpost & Chronopost for WooCommerce <= 3.0.2 - Authenticated (Subscriber+) SQL Injection

medium

The WCMultiShipping — Mondial Relay, Inpost & Chronopost for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...

CVSS:
6.5
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Jun 10, 2026

CVE-2026-52700 on NVD →

Mondial Relay &amp; Chronopost plugin for WooCommerce &#8211; WCMultiShipping [wc-multishipping] < 2.3.6

unknown

[en] Missing Authorization vulnerability in Mondial Relay WooCommerce - WCMultiShipping WCMultiShipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCMultiShipping: from n/a through 2.3.5.

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Dec 9, 2024

CVE-2023-48274 on NVD →

Mondial Relay &amp; Chronopost plugin for WooCommerce &#8211; WCMultiShipping [wc-multishipping] < 2.3.8

unknown

Update the WordPress WCMultiShipping plugin to the latest available version (at least 2.3.8). Unknown discovered and reported this Broken Access Control vulnerability in WordPress WCMultiShipping Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function t...

Affected:
up to 2.3.8
Fixed in:
2.3.8
Disclosed:
Nov 29, 2023

Chronopost & Mondial relay pour WooCommerce - WCMultiShipping <= 2.3.7 - Incorrect Authorization

medium

The UPS, Mondial Relay & Chronopost for WooCommerce – WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to an incorrect capability check on the wms_chronopost_test_credentials_ajax() function in all versions up to, and including, 2.3.7. This makes it possible for authenticated attack...

CVSS:
5.3
Affected:
up to 2.3.7
Fixed in:
2.3.8
Disclosed:
Nov 28, 2023

Mondial Relay &amp; Chronopost plugin for WooCommerce &#8211; WCMultiShipping [wc-multishipping] < 2.3.8

unknown

The UPS, Mondial Relay & Chronopost for WooCommerce – WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to an incorrect capability check on the wms_chronopost_test_credentials_ajax() function in all versions up to, and including, 2.3.7. This makes it possible for authenticated attack...

Affected:
up to 2.3.8
Fixed in:
2.3.8
Disclosed:
Nov 28, 2023

WCMultiShipping <= 2.3.5 - Missing Authorization to Log Export

medium

The WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wms_export_log function in all versions up to, and including, 2.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and view the plugins l...

CVSS:
4.3
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
Nov 21, 2023

CVE-2023-48274 on NVD →

Mondial Relay &amp; Chronopost plugin for WooCommerce &#8211; WCMultiShipping [wc-multishipping] < 2.3.6

unknown

The WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wms_export_log function in all versions up to, and including, 2.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and view the plugins l...

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Nov 21, 2023

Mondial Relay &amp; Chronopost plugin for WooCommerce &#8211; WCMultiShipping [wc-multishipping] < 2.3.8

unknown

The plugin does not have proper capability check on its wms_chronopost_test_credentials_ajax() function, allowing any authenticate duets, such as with subscriber, to test account credentials.

Affected:
up to 2.3.8
Fixed in:
2.3.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database