Input validation vulnerability in WooCommerce PDF Invoice Builder 1.2.90

The WooCommerce PDF Invoice Builder for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that without proper security measures, attackers can create invoice fields without having to log in or be an authorized user. To do this, they must trick an admin into clicking on a link or performing some other action. Versions of the WooCommerce PDF Invoice Builder up to and including 1.2.90 do not have the necessary security protection, making them vulnerable to this type of attack.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.