Sensitive Information Exposure in Print Invoice & Delivery Notes Plugin for WooCommerce
CVE-2024-13640
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-13640?
The Print Invoice & Delivery Notes for WooCommerce plugin is susceptible to sensitive information exposure due to improper access control in the 'wcdn/invoice' directory. This vulnerability allows unauthenticated attackers to access and extract sensitive data, including invoice files, stored in the /wp-content/uploads/wcdn/invoice directory, particularly when email attachments are enabled. This flaw highlights the critical need for enhanced security measures in WordPress plugins to protect sensitive data from unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Print Invoice & Delivery Notes for WooCommerce * <= 5.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved