Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Woocommerce Delivery Notes — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
woocommerce-delivery-notes
- 30000+ instalaciones activas
delivery notesinvoicepacking slipspdf invoicewoocommerce print invoice
Estado de mantenimiento
- Última versión conocida: 7.2.1
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): <8.0
Vulnerabilidades conocidas
10 CVEs conocidos registrados para Woocommerce Delivery Notes.
Reportadas entre 2023 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-56060
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 7.1.2 |
Exposición de información sensible del sistema a una esfera de control no autorizada |
Alta
7,5
|
< 7.1.2
|
7.1.2 |
2026-06-25 |
✓ corregido en la última versión
|
|
CVE-2026-25317
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 6.0.0 |
Falta de control de autorización |
Alta
7,5
|
< 6.0.0
|
6.0.0 |
2026-03-18 |
✓ corregido en la última versión
|
|
CVE-2026-24946
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 |
Falta de control de autorización |
Media
6,5
|
< 5.9.0
|
5.9.0 |
2026-02-03 |
✓ corregido en la última versión
|
|
CVE-2025-13773
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 |
Control incorrecto de la generación de código (inyección de código) |
Crítica
9,8
|
< 5.9.0
|
5.9.0 |
2025-12-23 |
✓ corregido en la última versión
|
|
CVE-2025-49239
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.6.0 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
5,4
|
< 5.6.0
|
5.6.0 |
2025-06-05 |
✓ corregido en la última versión
|
|
CVE-2024-13640
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0 |
Exposición de información sensible a un actor no autorizado |
Media
5,9
|
< 5.5.0
|
5.5.0 |
2025-03-07 |
✓ corregido en la última versión
|
|
CVE-2024-12210
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.4.1 |
Falta de control de autorización |
Media
4,3
|
< 5.4.1
|
5.4.1 |
2024-12-23 |
✓ corregido en la última versión
|
|
CVE-2024-4233
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.9.0 |
Falta de control de autorización |
Media
4,3
|
< 4.9.0
|
4.9.0 |
2024-04-26 |
✓ corregido en la última versión
|
CVE-2026-56060
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-25317
Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-24946
Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-13773
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-49239
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-13640
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/wcdn/invoice directory which can contain invoice files if an email attachment setting is enabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-12210
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to remove the shop's logo.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-4233
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 3 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2022-46795
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.3 |
Falta de control de autorización |
Media
6,5
|
< 4.7.3
|
4.7.3 |
2023-03-13 |
✓ corregido en la última versión
|
|
CVE-2023-0479
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 4.7.2
|
4.7.2 |
2023-02-02 |
✓ corregido en la última versión
|
|
—
|
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 |
— |
Desconocido
|
< 4.7.2
|
4.7.2 |
2023-02-02 |
✓ corregido en la última versión
|
CVE-2022-46795
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.2. This is due to missing or incorrect nonce validation on the ts_reset_tracking_setting function. This makes it possible for unauthenticated attackers to reset usage tracking via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-0479
The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be installed and active. This vulnerability is caused by a urldecode() after cleanup with esc_url_raw(), allowing double encoding.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2
Update the WordPress Print Invoice & Delivery Notes for WooCommerce plugin to the latest available version (at least 4.7.2).
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Print Invoice & Delivery Notes for WooCommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.7.2.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Woocommerce Delivery Notes actualizado — 7.2.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas