Sensitive Information Exposure in Print Invoice & Delivery Notes Plugin for WooCommerce
CVE-2024-13640

5.9MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
8 March 2025

Summary

The Print Invoice & Delivery Notes for WooCommerce plugin is susceptible to sensitive information exposure due to improper access control in the 'wcdn/invoice' directory. This vulnerability allows unauthenticated attackers to access and extract sensitive data, including invoice files, stored in the /wp-content/uploads/wcdn/invoice directory, particularly when email attachments are enabled. This flaw highlights the critical need for enhanced security measures in WordPress plugins to protect sensitive data from unauthorized access.

Affected Version(s)

Print Invoice & Delivery Notes for WooCommerce * <= 5.4.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.