CVE · Medium

CVE-2024-13640 — Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13640 Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.9 < 5.5.0 5.5.0 2025-03-07

CVE-2024-13640

The Print Invoice & Delivery Notes for WooCommerce plugin through version 5.4.1 contains a sensitive information exposure vulnerability that allows unauthenticated users to access invoice files stored in the /wp-content/uploads/wcdn/invoice directory. When the email attachment feature is enabled, invoice documents containing sensitive data become publicly accessible through insecure storage practices. An attacker can exploit this flaw without authentication to retrieve and view these confidential invoice files. The vulnerability has been addressed in version 5.5.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.