CVE-2024-3216: WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.4.2 - Missing Authorization to Unauthenticated Settings Reset
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wtpklistresetsettings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated attackers to reset all of the plugin's settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3216?
CVE-2024-3216 is considered to have a medium severity due to the potential for unauthorized modification of data.
How do I fix CVE-2024-3216?
To fix CVE-2024-3216, update the WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin to version 4.4.3 or later.
What versions are affected by CVE-2024-3216?
CVE-2024-3216 affects all versions of the plugin up to and including 4.4.2.
What is the impact of CVE-2024-3216?
The impact of CVE-2024-3216 is the potential for unauthorized users to modify plugin settings without proper permissions.
Is there a workaround for CVE-2024-3216?
Currently, the only recommended workaround for CVE-2024-3216 is to upgrade the plugin to the latest version.