QID 150661

Date Published: 2023-03-23

QID 150661: WordPress WooCommerce PDF Invoices and Packing Slips Plugin: Cross-Site Request Forgery Vulnerability (CVE-2022-47148)

WooCommerce PDF Invoice and Packing Slips is a WooCommerce extension plugin that automatically adds a PDF invoice to the order confirmation emails sent out to your customers.

The WordPress WooCommerce PDF Invoices and Packing Slips Plugin has been found to contain a security vulnerability known as Cross Site Request Forgery (CSRF). This vulnerability could potentially be exploited by an attacker to force users with higher privileges to perform unintended actions without their knowledge or consent. Such actions could include altering or deleting sensitive information, making unauthorized purchases, or performing other actions that could compromise the security and integrity of the system.

Affected versions:
WooCommerce PDF Invoice and Packing Slips prior to 3.2.6

QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.

Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive browser-based information.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Customers are advised to upgrade to WooCommerce PDF Invoice and Packing Slips 3.2.6 or later version to remediate this vulnerability.

    CVEs related to QID 150661

    Software Advisories
    Advisory ID Software Component Link
    patchstack URL Logo patchstack.com/database/vulnerability/woocommerce-pdf-invoices-packing-slips/wordpress-pdf-invoices-packing-slips-for-woocommerce-plugin-3-2-5-cross-site-request-forgery-csrf?_s_id=cve