What the vulnerability does
01Description
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Print Invoice & Delivery Notes for WooCommerce plugin through version 4.8.1 does not properly check user permissions before allowing modifications to invoices and delivery notes. A logged-in user with low privileges can alter invoice data or delivery note content that should be restricted to administrators or shop managers. This affects data integrity but does not expose sensitive information or disrupt site availability.
What an attacker can do
03Attacker Capabilities
Modify invoice and delivery note data without proper authorization.
Potential impact on your site
04Site Impact
Invoices and delivery notes may be altered by unauthorized users, affecting order records and customer trust.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WooCommerce user account (e.g., customer or subscriber).
Key dates
06Disclosure timeline
May 8, 2024
CVE published
April 28, 2026
Record updated