CVE-2024-13640
The Print Invoice & Delivery Notes for WooCommerce plugin through version 5.4.1 contains a sensitive information exposure vulnerability that allows unauthenticated users to access invoice files stored in the /wp-content/uploads/wcdn/invoice directory. When the email attachment feature is enabled, invoice documents containing sensitive data become publicly accessible through insecure storage practices. An attacker can exploit this flaw without authentication to retrieve and view these confidential invoice files. The vulnerability has been addressed in version 5.5.0 and later.
Based on public CVE data (MITRE/NVD).