2 results (0.004 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

23 Dec 2024 — The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove the shop's logo. El complemento Print Invoice & Delivery Notes para WooCommerce para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una... • https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3209682%40woocommerce-delivery-notes&new=3209682%40woocommerce-delivery-notes&sfp_email=&sfph_mail= • CWE-862: Missing Authorization •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 1

02 Feb 2023 — The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding. El complemento Print Invoice & Delivery Notes para WooCommerce Wo... • https://wpscan.com/vulnerability/50963747-ae8e-42b4-bb42-cc848be7b92e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •