Tyche Softwares Print Invoice & Delivery Notes for WooCommerce
cpe:2.3:a:tychesoftwares:print_invoice_&_delivery_notes_for_woocommerce:*:*:*:*:wordpress:*:*
- <= 5.4.1
A vulnerability allowing sensitive information exposure exists in the Print Invoice & Delivery Notes for WooCommerce plugin, affecting all versions through 5.4.1. The issue arises from an unprotected 'wcdn/invoice' directory, where sensitive data, including invoice files, can be accessed by unauthenticated users. This exposure occurs if the email attachment feature is enabled.
Exploitation of this vulnerability allows unauthenticated users to access sensitive invoice data stored in an unprotected directory on the server.
To reproduce this vulnerability, enable the email attachment option in the Print Invoice & Delivery Notes for WooCommerce plugin. Afterward, invoices will be saved as PDF files in the '/wp-content/uploads/wcdn/invoice/' directory. An unauthenticated user can then access this directory and download the invoice files, thereby exploiting the vulnerability.
Users are advised to update the Print Invoice & Delivery Notes for WooCommerce plugin to version 5.5.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.