CVE · Medium

CVE-2023-0479 — Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0479 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.7.2 4.7.2 2023-02-02

CVE-2023-0479

The Print Invoice & Delivery Notes for WooCommerce plugin before version 4.7.2 contains a reflected cross-site scripting vulnerability where a GET parameter is output unsafely in an admin note displayed on the WooCommerce orders page. Attackers can exploit this flaw by targeting users who possess the edit_others_shop_orders capability, provided WooCommerce is installed and enabled. The vulnerability stems from the use of urldecode() applied after esc_url_raw() sanitization, which permits double encoding to bypass the security measures.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.