CVE-2025-24373
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-24373 is a vulnerability affecting the woocommerce-pdf-invoices-packing-slips extension for WooCommerce. This issue allows unauthorized users to access any PDF document from a store by manipulating a guest document link. The vulnerability arises when the document access is set to "guest" and the user is logged out. The confidentiality of sensitive documents is compromised for all stores using the plugin with the guest access option enabled. Version 4.0.0 addresses this vulnerability, and users are advised to upgrade as soon as possible. There are currently no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.