WCMultiShipping — Mondial Relay, Inpost & Chronopost for WooCommerce <= 3.0.2 - Authenticated (Subscriber+) SQL Injection
medium
The WCMultiShipping — Mondial Relay, Inpost & Chronopost for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...
- CVSS:
- 6.5
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.3
- Disclosed:
- Jun 10, 2026
CVE-2026-52700 on NVD →
Mondial Relay & Chronopost plugin for WooCommerce – WCMultiShipping [wc-multishipping] < 2.3.6
unknown
[en] Missing Authorization vulnerability in Mondial Relay WooCommerce - WCMultiShipping WCMultiShipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCMultiShipping: from n/a through 2.3.5.
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.6
- Disclosed:
- Dec 9, 2024
CVE-2023-48274 on NVD →
Mondial Relay & Chronopost plugin for WooCommerce – WCMultiShipping [wc-multishipping] < 2.3.8
unknown
Update the WordPress WCMultiShipping plugin to the latest available version (at least 2.3.8).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress WCMultiShipping Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function t...
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Nov 29, 2023
Chronopost & Mondial relay pour WooCommerce - WCMultiShipping <= 2.3.7 - Incorrect Authorization
medium
The UPS, Mondial Relay & Chronopost for WooCommerce – WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to an incorrect capability check on the wms_chronopost_test_credentials_ajax() function in all versions up to, and including, 2.3.7. This makes it possible for authenticated attack...
- CVSS:
- 5.3
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.8
- Disclosed:
- Nov 28, 2023
Mondial Relay & Chronopost plugin for WooCommerce – WCMultiShipping [wc-multishipping] < 2.3.8
unknown
The UPS, Mondial Relay & Chronopost for WooCommerce – WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to an incorrect capability check on the wms_chronopost_test_credentials_ajax() function in all versions up to, and including, 2.3.7. This makes it possible for authenticated attack...
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
- Disclosed:
- Nov 28, 2023
WCMultiShipping <= 2.3.5 - Missing Authorization to Log Export
medium
The WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wms_export_log function in all versions up to, and including, 2.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and view the plugins l...
- CVSS:
- 4.3
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.6
- Disclosed:
- Nov 21, 2023
CVE-2023-48274 on NVD →
Mondial Relay & Chronopost plugin for WooCommerce – WCMultiShipping [wc-multishipping] < 2.3.6
unknown
The WCMultiShipping plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wms_export_log function in all versions up to, and including, 2.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to export and view the plugins l...
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.6
- Disclosed:
- Nov 21, 2023
Mondial Relay & Chronopost plugin for WooCommerce – WCMultiShipping [wc-multishipping] < 2.3.8
unknown
The plugin does not have proper capability check on its wms_chronopost_test_credentials_ajax() function, allowing any authenticate duets, such as with subscriber, to test account credentials.
- Affected:
- up to 2.3.8
- Fixed in:
- 2.3.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database