Unauthorized Data Access Vulnerability in WooCommerce PDF Invoice Builder by WordPress
CVE-2023-4245
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 31 August 2023
Summary
The WooCommerce PDF Invoice Builder plugin for WordPress has a vulnerability that allows unauthorized access to invoice data. This is due to a missing capability check in the GetInvoiceDetail function, which affects all versions up to and including 1.2.89. A malicious user with a subscriber account can exploit this flaw to view sensitive invoices by simply guessing the order ID and invoice ID, potentially exposing private financial information.
Affected Version(s)
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more * <= 1.2.91
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka