plugin

Woocommerce Pdf Vouchers Vulnerabilities

12 known security issues reported for the Woocommerce Pdf Vouchers WordPress plugin. Most recent disclosed Dec 31, 2024.

2 critical 1 high 3 medium

Running Woocommerce Pdf Vouchers on your site? Check whether your installed version is affected.

Scan your site free

PDF Product Vouchers for WooCommerce [woocommerce-pdf-vouchers] < 4.9.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPWeb WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.9.

Affected:
up to 4.9.9
Fixed in:
4.9.9
Disclosed:
Dec 31, 2024

CVE-2024-56265 on NVD →

WooCommerce PDF Vouchers < 4.9.9 - Reflected Cross-Site Scripting

medium

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 4.9.9 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

CVSS:
6.1
Affected:
up to 4.9.9
Fixed in:
4.9.9
Disclosed:
Dec 19, 2024

CVE-2024-56265 on NVD →

PDF Product Vouchers for WooCommerce [woocommerce-pdf-vouchers] < 4.9.9

unknown

[en] Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.9.

Affected:
up to 4.9.9
Fixed in:
4.9.9
Disclosed:
Dec 18, 2024

CVE-2024-54383 on NVD →

WooCommerce PDF Vouchers < 4.9.9 - Authentication Bypass

critical

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in all versions up to 4.9.9 (exclusive). This makes it possible for unauthenticated attackers to log in as other users.

CVSS:
9.8
Affected:
up to 4.9.9
Fixed in:
4.9.9
Disclosed:
Dec 11, 2024

CVE-2024-54383 on NVD →

PDF Product Vouchers for WooCommerce [woocommerce-pdf-vouchers] < 4.9.5

unknown

[en] Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4.

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Nov 1, 2024

CVE-2024-39650 on NVD →

PDF Product Vouchers for WooCommerce [woocommerce-pdf-vouchers] < 4.9.5

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Aug 13, 2024

CVE-2024-39651 on NVD →

WooCommerce PDF Vouchers <= 4.9.4 - Unauthenticated Arbitrary File Deletion

critical

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 4.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote c...

CVSS:
9.1
Affected:
up to 4.9.4
Fixed in:
4.9.5
Disclosed:
Aug 1, 2024

CVE-2024-39651 on NVD →

WooCommerce PDF Vouchers <= 4.9.4 - Missing Authorization

medium

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions like 'woo_vou_trigger_upgrades', 'woo_vou_admin_run_v430_udater_script', 'woo_vou_activate_license', 'woo_vou_generate_system_log' and many more in all versions up to, and incl...

CVSS:
6.5
Affected:
up to 4.9.4
Fixed in:
4.9.5
Disclosed:
Aug 1, 2024

CVE-2024-39650 on NVD →

WooCommerce PDF Vouchers <= 4.9.4 - Reflected Cross-Site Scripting

medium

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c...

CVSS:
6.1
Affected:
up to 4.9.4
Fixed in:
4.9.5
Disclosed:
Aug 1, 2024

CVE-2024-39652 on NVD →

PDF Product Vouchers for WooCommerce [woocommerce-pdf-vouchers] < 4.9.5

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.

Affected:
up to 4.9.5
Fixed in:
4.9.5
Disclosed:
Aug 1, 2024

CVE-2024-39652 on NVD →

PDF Product Vouchers for WooCommerce [woocommerce-pdf-vouchers] < 4.9.4

unknown

[en] The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the plugin. This makes it possible for unauthenticated attackers to log in as any ex...

Affected:
up to 4.9.4
Fixed in:
4.9.4
Disclosed:
Jul 24, 2024

CVE-2024-7027 on NVD →

WooCommerce - PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor

high

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the plugin. This makes it possible for unauthenticated attackers to log in as any existin...

CVSS:
7.3
Affected:
up to 4.9.3
Fixed in:
4.9.4
Disclosed:
Jul 23, 2024

CVE-2024-7027 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database