cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwebappick-pdf-invoice-for-woocommerce webappick-pdf-invoice-for-woocommerce

Direction: descending
May 09, 2025

Challan – PDF Invoice & Packing Slip for WooCommerce # CVE-2025-47462

CVE, Research URL

CVE-2025-47462

Date
May 07, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Ohidul Islam Challan allows Privilege Escalation. This issue affects Challan: from n/a through 3.7.58.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Challan – PDF Invoice & Packing Slip for WooCommerce # c0e638522757dc0e018dc791befa7fdc871f818a

Date
Mar 21, 2023
Research Description
Challan &#8211; PDF Invoice &amp; Packing Slip for WooCommerce [webappick-pdf-invoice-for-woocommerce] < 3.4.9 WordPress Challan – PDF Invoice & Packing Slip for WooCommerce Plugin <= 3.4.8 is vulnerable to Cross Site Request Forgery (CSRF) No patched version is available. No reply from the vendor. Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Challan – PDF Invoice & Packing Slip for WooCommerce Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.
Affected versions
Min -, max -.
Status
vulnerable