All 2 CVE vulnerabilities found in MyParcel, with AI-generated Chinese analysis, references, and POCs.
Vendor: richardperdaan
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-8678 | MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions CWE-862 | 4.3 | Medium | 2026-07-11 |
| CVE-2024-9608 | MyParcel <= 4.24.1 - Reflected Cross-Site Scripting CWE-79 | 6.1 | Medium | 2024-12-13 |
All 2 known CVE vulnerabilities affecting MyParcel with full Chinese analysis, references, and POCs where available.