CVE-2025-24373

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 4, 2025
Updated: Feb 19, 2025
CWE ID 200

Summary

CVE-2025-24373 is a vulnerability affecting the woocommerce-pdf-invoices-packing-slips extension for WooCommerce. This issue allows unauthorized users to access any PDF document from a store by manipulating a guest document link. The vulnerability arises when the document access is set to "guest" and the user is logged out. The confidentiality of sensitive documents is compromised for all stores using the plugin with the guest access option enabled. Version 4.0.0 addresses this vulnerability, and users are advised to upgrade as soon as possible. There are currently no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share