Lucene search

K
wpvulndbWpvulndbWPVDB-ID:01D16745-3EA3-4451-B257-2EA21B1A56F5
HistorySep 07, 2023 - 12:00 a.m.

WooCommerce PDF Invoice Builder < 1.2.92 - Subscriber+ Arbitrary Invoice Access

2023-09-0700:00:00
wpscan.com
6
woocommerce
pdf
invoice
builder
unauthorized access
authenticated users

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

28.8%

Description The plugin does not have authorisation in the GetInvoiceDetail function, allowing any authenticated users, such as subscriber to access arbitrary invoice by knowing or guessing the order and invoice IDs

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

28.8%

Related for WPVDB-ID:01D16745-3EA3-4451-B257-2EA21B1A56F5