First published: Fri May 17 2024(Updated: )
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | <=4.2.1 | |
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | <=4.2.1 | |
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | <4.3.0 |
Update to 4.3.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51546 is a high severity vulnerability that allows privilege escalation in the affected plugin.
To fix CVE-2023-51546, update the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin to version 4.3.0 or later.
CVE-2023-51546 affects all versions of the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin up to 4.2.1.
CVE-2023-51546 is categorized as an improper privilege management vulnerability.
Yes, CVE-2023-51546 can be exploited remotely to escalate privileges.