Multiparcels develops a WooCommerce shipping plugin that integrates parcel logistics functionality into e-commerce platforms, with its disclosed vulnerabilities centered on cross-site scripting issues in web-facing input handling. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Multiparcels over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2843HIGH The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.15 does not properly sanitize and escape a parameter before using it in an SQL statement, which could allow a | Aug 7, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-3365HIGH The MultiParcels Shipping For WooCommerce WordPress plugin before 1.14.14 does not have authorisation when deleting shipment, allowing any authenticated users, such as subscriber t | Aug 7, 2023 | 8.1 | 22 | NO | NO |
CVE-2023-3954MEDIUM The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cros | Aug 21, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-3671MEDIUM The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.4 does not sanitise and escape various parameters before outputting it back in the page, leading to a Reflect | Aug 7, 2023 | 6.1 | 19 | NO | NO |
CVE-2025-62995MEDIUM Missing Authorization vulnerability in multiparcels MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Cont | Dec 9, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-32095MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in MultiParcels MultiParcels Shipping For WooCommerce.This issue affects MultiParcels Shipping For WooCommerce: from n/a before 1.16 | Apr 15, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-3366MEDIUM The MultiParcels Shipping For WooCommerce WordPress plugin before 1.15.2 does not have CRSF check when deleting a shipment, allowing attackers to make any logged in user, delete ar | Aug 21, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Multiparcels.
Media articles that mention a CVE ID that affects a product developed by Multiparcels — matched by CVE ID, not by vendor name.