VYPR
Medium severity6.5NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2026-24946

CVE-2026-24946

Description

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Print Invoice & Delivery Notes for WooCommerce up to version 5.8.0 allows attackers to exploit broken access controls.

Vulnerability

Overview

The Print Invoice & Delivery Notes for WooCommerce plugin (woocommerce-delivery-notes) for WordPress contains a missing authorization vulnerability affecting versions from n/a through 5.8.0. This issue arises from incorrectly configured access control security levels, allowing exploitation of broken access controls [1].

Exploitation

Details

The vulnerability is classified as Broken Access Control, meaning there is a missing authorization, authentication, or nonce token check in a function. This could allow an unprivileged user to execute higher-privileged actions [1]. Attackers can potentially target thousands of websites in mass-exploit campaigns, regardless of site traffic or popularity [1].

Impact

If exploited, an attacker could gain unauthorized access to functions or data that should be restricted, potentially compromising the security of WooCommerce-based online stores. The CVSS v3 base score is 6.5 (Medium), indicating a moderate severity risk [1].

Mitigation

The vendor has released version 5.9.0 which resolves the vulnerability. Users are strongly advised to update immediately. Patchstack has also issued a mitigation rule to block attacks until the update is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.