plugin

Woocommerce Delivery Notes Vulnerabilities

19 known security issues reported for the Woocommerce Delivery Notes WordPress plugin. Most recent disclosed Jun 25, 2026.

1 critical 9 medium

Running Woocommerce Delivery Notes on your site? Check whether your installed version is affected.

Scan your site free

Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 - Unauthenticated Information Exposure

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.1.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 7.1.1
Fixed in:
7.1.2
Disclosed:
Jun 25, 2026

CVE-2026-56060 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 5.9.0 - Missing Authorization

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.9.0
Fixed in:
6.0.0
Disclosed:
Mar 18, 2026

CVE-2026-25317 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] <= 5.8.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.

Affected:
up to 5.8.0
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-24946 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Missing Authorization

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.8.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.8.0
Fixed in:
5.9.0
Disclosed:
Feb 3, 2026

CVE-2026-24946 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0

unknown

[en] The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled...

Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Dec 24, 2025

CVE-2025-13773 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution

critical

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in D...

CVSS:
9.8
Affected:
up to 5.8.0
Fixed in:
5.9.0
Disclosed:
Dec 23, 2025

CVE-2025-13773 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.6.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce allows Cross Site Request Forgery. This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 5.5.0.

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Jun 6, 2025

CVE-2025-49239 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 5.5.0 - Cross-Site Request Forgery

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action gran...

CVSS:
4.3
Affected:
up to 5.5.0
Fixed in:
5.6.0
Disclosed:
Jun 5, 2025

CVE-2025-49239 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0

unknown

[en] The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/u...

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
Mar 8, 2025

CVE-2024-13640 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 5.4.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/upload...

CVSS:
5.9
Affected:
up to 5.4.1
Fixed in:
5.5.0
Disclosed:
Mar 7, 2025

CVE-2024-13640 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.4.1

unknown

[en] The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-lev...

Affected:
up to 5.4.1
Fixed in:
5.4.1
Disclosed:
Dec 24, 2024

CVE-2024-12210 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 5.4.0 - Missing Authorization to Authenticated (Subscriber+) Logo Deletion

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action in all versions up to, and including, 5.4.0. This makes it possible for authenticated attackers, with Subscriber-level ac...

CVSS:
4.3
Affected:
up to 5.4.0
Fixed in:
5.4.1
Disclosed:
Dec 23, 2024

CVE-2024-12210 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.3

unknown

[en] Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.7.2.

Affected:
up to 4.7.3
Fixed in:
4.7.3
Disclosed:
Dec 13, 2024

CVE-2022-46795 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.9.0

unknown

[en] Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ:...

Affected:
up to 4.9.0
Fixed in:
4.9.0
Disclosed:
May 8, 2024

CVE-2024-4233 on NVD →

Multiple Plugins by tychesoftwares <= (Various Versions) - Missing Authorization to Notice Dismissal

medium

Multiple plugins for WordPress by tychesoftwares are vulnerable to unauthorized modification of data due to a missing capability check on the ts_admin_notices() function in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss tracking notices.

CVSS:
4.3
Affected:
up to 4.8.1
Fixed in:
4.9.0
Disclosed:
Apr 26, 2024

CVE-2024-4233 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2

unknown

[en] The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be...

Affected:
up to 4.7.2
Fixed in:
4.7.2
Disclosed:
Jan 16, 2024

CVE-2023-0479 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 4.7.2 - Cross-Site Request Forgery via ts_reset_tracking_setting

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7.2. This is due to missing or incorrect nonce validation on the ts_reset_tracking_setting function. This makes it possible for unauthenticated attackers to reset usage...

CVSS:
4.3
Affected:
up to 4.7.2
Fixed in:
4.7.3
Disclosed:
Mar 13, 2023

CVE-2022-46795 on NVD →

Print Invoice & Delivery Notes for WooCommerce <= 4.7.1 - Reflected Cross-Site Scripting

medium

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Feb 2, 2023

CVE-2023-0479 on NVD →

Print Invoice &amp; Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2

unknown

Update the WordPress Print Invoice & Delivery Notes for WooCommerce plugin to the latest available version (at least 4.7.2). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Print Invoice & Delivery Notes for WooCommerce Plugin. This could allow a malicious actor to i...

Affected:
up to 4.7.2
Fixed in:
4.7.2
Disclosed:
Feb 2, 2023

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database