WordPress 插件 WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels 在 5.0.2 及以下版本中存在不安全的直接对象引用(Insecure Direct Object Reference)漏洞。该漏洞存在于通过 函数在 阶段调用的 处理程序中的 参数。 此漏洞的原因在于,该处理程序在攻击者提供的(base64 编码) 值等于订单的账单电子邮件地址时,即授权访问该订单的可打印文档。然而,账单电
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| webtoffee | WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels | ≤ 5.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| webtoffee | WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels | 0 ~ 5.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet