CVE Database /
CVE-2023-51546
CVE · High
CVE-2023-51546 — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-51546
|
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.3.0 |
Improper Privilege Management |
High
7.2
|
< 4.3.0
|
4.3.0 |
2023-12-27 |
—
|
CVE-2023-51546
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin before version 4.3.0 contains a privilege escalation vulnerability that allows attackers with low-level account access to gain elevated permissions. A malicious actor exploiting this flaw could potentially obtain administrative control of the affected WordPress site. The issue was discovered by Rafie Muhammad and has been resolved in version 4.3.0 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings