Sensitive Information Exposure in Print Invoice & Delivery Notes Plugin for WooCommerce
CVE-2024-13640
5.9MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 8 March 2025
Summary
The Print Invoice & Delivery Notes for WooCommerce plugin is susceptible to sensitive information exposure due to improper access control in the 'wcdn/invoice' directory. This vulnerability allows unauthenticated attackers to access and extract sensitive data, including invoice files, stored in the /wp-content/uploads/wcdn/invoice directory, particularly when email attachments are enabled. This flaw highlights the critical need for enhanced security measures in WordPress plugins to protect sensitive data from unauthorized access.
Affected Version(s)
Print Invoice & Delivery Notes for WooCommerce * <= 5.4.1
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tim Coen