CVE · High

CVE-2024-3047 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3047 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 Server-Side Request Forgery (SSRF) High 7.2 < 3.8.1 3.8.1 2024-04-24

CVE-2024-3047

The PDF Invoices & Packing Slips for WooCommerce plugin through version 3.8.0 contains a server-side request forgery vulnerability in the transform() function that permits unauthenticated attackers to conduct arbitrary HTTP requests from the affected server. This flaw enables attackers to access and potentially alter data stored on internal services by forcing the application to make requests on their behalf. The vulnerability was addressed in version 3.8.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.