CVE · High

CVE-2023-51546 — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-51546 WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.3.0 Improper Privilege Management High 7.2 < 4.3.0 4.3.0 2023-12-27

CVE-2023-51546

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin before version 4.3.0 contains a privilege escalation vulnerability that allows attackers with low-level account access to gain elevated permissions. A malicious actor exploiting this flaw could potentially obtain administrative control of the affected WordPress site. The issue was discovered by Rafie Muhammad and has been resolved in version 4.3.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.