PT-2025-5351 · WordPress · Woocommerce Pdf Invoices & Packing Slips

Alexmigf

·

Published

2025-02-04

·

Updated

2025-02-05

·

CVE-2025-24373

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions woocommerce-pdf-invoices-packing-slips versions prior to 4.0.0
Description This issue allows unauthorized users to access any PDF document from a store if they have access to a guest document link and replace the URL variable my-account with bulk. The problem occurs when the store's document access is set to "guest" and the user is logged out, compromising the confidentiality of sensitive documents. All stores using the plugin with the guest access option enabled are affected.
Recommendations For versions prior to 4.0.0, upgrade to version 4.0.0 or later to resolve the issue. As a temporary workaround, consider disabling the guest access option to minimize the risk of exploitation. Restrict access to sensitive documents until the issue is resolved.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-24373
GHSA-3J9M-CP35-94FR

Affected Products

Woocommerce Pdf Invoices & Packing Slips