CVE · Medium

CVE-2022-47148 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.2.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-47148 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.2.6 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.2.6 3.2.6 2023-01-27

CVE-2022-47148

The WooCommerce PDF Invoices & Packing Slips plugin before version 3.2.6 contains a cross-site request forgery vulnerability that could enable an attacker to trick authenticated users into performing unintended actions while logged in, such as changing passwords to grant the attacker administrative access. Muhammad Daffa identified and disclosed this flaw, which affects all versions prior to 3.2.6 where it was remedied.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.