WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Woocommerce Delivery Notes?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Woocommerce Delivery Notes — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: woocommerce-delivery-notes
  • 30000+ instalaciones activas

delivery notesinvoicepacking slipspdf invoicewoocommerce print invoice

Estado de mantenimiento

  • Última versión conocida: 7.2.1
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): <8.0

Vulnerabilidades conocidas

10 CVEs conocidos registrados para Woocommerce Delivery Notes. Reportadas entre 2023 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-56060 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 7.1.2 Exposición de información sensible del sistema a una esfera de control no autorizada Alta 7,5 < 7.1.2 7.1.2 2026-06-25 ✓ corregido en la última versión
CVE-2026-25317 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 6.0.0 Falta de control de autorización Alta 7,5 < 6.0.0 6.0.0 2026-03-18 ✓ corregido en la última versión
CVE-2026-24946 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 Falta de control de autorización Media 6,5 < 5.9.0 5.9.0 2026-02-03 ✓ corregido en la última versión
CVE-2025-13773 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 Control incorrecto de la generación de código (inyección de código) Crítica 9,8 < 5.9.0 5.9.0 2025-12-23 ✓ corregido en la última versión
CVE-2025-49239 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.6.0 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 5.6.0 5.6.0 2025-06-05 ✓ corregido en la última versión
CVE-2024-13640 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0 Exposición de información sensible a un actor no autorizado Media 5,9 < 5.5.0 5.5.0 2025-03-07 ✓ corregido en la última versión
CVE-2024-12210 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.4.1 Falta de control de autorización Media 4,3 < 5.4.1 5.4.1 2024-12-23 ✓ corregido en la última versión
CVE-2024-4233 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.9.0 Falta de control de autorización Media 4,3 < 4.9.0 4.9.0 2024-04-26 ✓ corregido en la última versión

CVE-2026-56060

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-25317

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-24946

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-13773

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-49239

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13640

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/wcdn/invoice directory which can contain invoice files if an email attachment setting is enabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-12210

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove the shop's logo.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-4233

Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 3 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2022-46795 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.3 Falta de control de autorización Media 6,5 < 4.7.3 4.7.3 2023-03-13 ✓ corregido en la última versión
CVE-2023-0479 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.7.2 4.7.2 2023-02-02 ✓ corregido en la última versión
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 Desconocido < 4.7.2 4.7.2 2023-02-02 ✓ corregido en la última versión

CVE-2022-46795

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.2. This is due to missing or incorrect nonce validation on the ts_reset_tracking_setting function. This makes it possible for unauthenticated attackers to reset usage tracking via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-0479

The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Cómo solucionarlo

Mantén Woocommerce Delivery Notes actualizado — 7.2.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.