Sensitive Information Exposure in Print Invoice & Delivery Notes Plugin for WooCommerce
CVE-2024-13640
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-13640?
The Print Invoice & Delivery Notes for WooCommerce plugin is susceptible to sensitive information exposure due to improper access control in the 'wcdn/invoice' directory. This vulnerability allows unauthenticated attackers to access and extract sensitive data, including invoice files, stored in the /wp-content/uploads/wcdn/invoice directory, particularly when email attachments are enabled. This flaw highlights the critical need for enhanced security measures in WordPress plugins to protect sensitive data from unauthorized access.
Affected Version(s)
Print Invoice & Delivery Notes for WooCommerce * <= 5.4.1