CVE · Medium

CVE-2024-3216 — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.4.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3216 WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.4.3 Missing Authorization Medium 5.3 < 4.4.3 4.4.3 2024-04-05

CVE-2024-3216

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin before version 4.4.3 contains a broken access control flaw where insufficient authorization checks allow unauthenticated or low-privilege users to perform actions restricted to higher-privileged accounts. The vulnerability stems from missing authentication and nonce token validation in one or more functions. This issue was patched in version 4.4.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.