CVE-2025-62995
Description
Missing Authorization vulnerability in multiparcels MultiParcels Shipping For WooCommerce multiparcels-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiParcels Shipping For WooCommerce: from n/a through <= 1.30.12.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
MultiParcels Shipping For WooCommerce ≤1.30.12 has a missing authorization vulnerability allowing unprivileged users to exploit incorrectly configured access control.
The MultiParcels Shipping For WooCommerce plugin for WordPress versions up to and including 1.30.12 contains a missing authorization vulnerability. The issue stems from a broken access control mechanism, where the plugin fails to properly verify user permissions or nonce tokens in certain functions, leading to incorrectly configured access control security levels [1].
Exploitation of this vulnerability does not require authentication, as an unprivileged user can trigger higher-privileged actions without proper authorization checks. The attack surface is accessible via the plugin functionality that lacks sufficient access control, potentially allowing attackers to perform unauthorized operations [1].
The impact of successful exploitation is limited to unauthorized access to certain plugin features, but the vulnerability is considered low severity and unlikely to be exploited in mass campaigns. However, it has been noted that similar vulnerabilities are used in mass-exploit campaigns targeting thousands of websites [1].
Mitigation is available by updating to version 1.30.13 or later, which resolves the missing authorization issue. Patchstack users can enable auto-updates for vulnerable plugins. As an immediate action, users should update the plugin or seek assistance from their hosting provider [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.30.12
- Range: <=1.30.12
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.