What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.
Explanation of Vulnerability in Simple Terms
The PDF Invoices and Packing Slips For WooCommerce plugin through version 1.3.7 deserializes untrusted data without validation. An authenticated attacker with low privileges can exploit this to read sensitive data or modify site content. The vulnerability affects the entire WooCommerce installation due to scope change.
What an attacker can do
Read sensitive data or modify site content by sending a crafted request.
Potential impact on your site
Attackers with customer or subscriber accounts can access confidential data or alter invoices and orders.
Conditions required to exploit
Attacker must have a low-privilege WooCommerce account; no user interaction required.
Key dates
External resources
Related vulnerabilities