Unauthorized Data Access Vulnerability in WooCommerce PDF Invoice Builder by WordPress
CVE-2023-4245
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 August 2023
What is CVE-2023-4245?
The WooCommerce PDF Invoice Builder plugin for WordPress has a vulnerability that allows unauthorized access to invoice data. This is due to a missing capability check in the GetInvoiceDetail function, which affects all versions up to and including 1.2.89. A malicious user with a subscriber account can exploit this flaw to view sensitive invoices by simply guessing the order ID and invoice ID, potentially exposing private financial information.
Affected Version(s)
WooCommerce PDF Invoice Builder, Create invoices, packing slips and more * <= 1.2.91