CVE-2024-12210 – Print Invoice & Delivery Notes for WooCommerce <= 5.4.0 - Missing Authorization to Authenticated (Subscriber+) Logo Deletion
https://notcve.org/view.php?id=CVE-2024-12210
23 Dec 2024 — The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove the shop's logo. El complemento Print Invoice & Delivery Notes para WooCommerce para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una... • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3209682%40woocommerce-delivery-notes&new=3209682%40woocommerce-delivery-notes&sfp_email=&sfph_mail= • CWE-862: Missing Authorization •
CVE-2023-0479 – Print Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS
https://notcve.org/view.php?id=CVE-2023-0479
02 Feb 2023 — The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding. El complemento Print Invoice & Delivery Notes para WooCommerce Wo... • https://wpscan.com/vulnerability/50963747-ae8e-42b4-bb42-cc848be7b92e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •