Extension WordPress

Vulnérabilités WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

Cette page rassemble les failles publiées pour WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

7 fiches

CVE-2026-49056 Moyenne · 5,3
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.4 – Unauthenticated Information Exposure

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.4. This makes it possible for unauthenticated attackers to extract…

Versions affectées

*-4.9.4

Correctif

4.9.5

Publication

03/06/2026

CVE-2025-24644 Moyenne · 4,4
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.7.1 – Authenticated (Shop Manager+) Stored Cross-Site Scripting

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-4.7.1

Correctif

4.7.2

Publication

24/01/2025

CVE-2024-3216 Moyenne · 5,3
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.4.2 – Missing Authorization to Unauthenticated Settings Reset

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including,…

Versions affectées

*-4.4.2

Correctif

4.4.3

Publication

05/04/2024

CVE-2024-22288 Moyenne · 6,1
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.4.0 – Reflected Cross-Site Scripting

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting parameter in versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-4.4.0

Correctif

4.4.1

Publication

26/03/2024

CVE-2024-0957 Moyenne · 6,1
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.4.1 – Unauthenticated Stored Cross-Site Scripting

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization…

Versions affectées

*-4.4.1

Correctif

4.4.2

Publication

21/03/2024

CVE-2023-7068 Moyenne · 4,3
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.3.0 – Missing Authorization to Order Export

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0.…

Versions affectées

*-4.3.0

Correctif

4.3.1

Publication

02/01/2024

CVE-2023-51546 Élevée · 7,2
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

WooCommerce PDF Invoices <= 4.2.1 – Authenticated(Shop Manager+) Arbitrary Options Update via JSON Import

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to arbitrary options updates via the JSON import functionality in all versions up to, and including, 4.2.1. This makes it possible for…

Versions affectées

*-4.2.1

Correctif

4.3.0

Publication

27/12/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités