First published: Sat Mar 08 2025(Updated: )
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/wcdn/invoice directory which can contain invoice files if an email attachment setting is enabled.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Print Invoice & Delivery Notes for WooCommerce | <=5.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13640 is classified as a high-severity vulnerability due to its potential for sensitive information exposure.
To fix CVE-2024-13640, update the Print Invoice & Delivery Notes for WooCommerce plugin to version 5.4.2 or later.
CVE-2024-13640 allows unauthenticated attackers to access sensitive information stored in the 'wcdn/invoice' directory.
CVE-2024-13640 affects all versions of the Print Invoice & Delivery Notes for WooCommerce plugin up to and including version 5.4.1.
Any website using the vulnerable versions of the Print Invoice & Delivery Notes for WooCommerce plugin is at risk of CVE-2024-13640.