Junglewise Threat Intelligence

CVE-2026-56060: Tyche Softwares Print Invoice & Delivery Notes for WooCommerce data exposure

CVE-2026-56060 · Severity: high · CVSS 7.5 · Published 2026-06-26

Vendors: Tyche Softwares.

Executive brief

A vulnerability in the Print Invoice & Delivery Notes plugin for WooCommerce allows unauthorized individuals to access sensitive information. This plugin is used by online stores to generate and manage customer billing and shipping documents. An exploit could lead to the exposure of private customer data or order details, potentially resulting in privacy violations and reputational damage.

Technical details

The Print Invoice & Delivery Notes for WooCommerce plugin (versions <= 7.1.1) is vulnerable to unauthenticated sensitive data exposure. The flaw is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), indicating that sensitive data is accessible without requiring any user authentication or specific privileges. An attacker can exploit this over the network to view information that should be restricted to authorized users or administrators. The issue is resolved in version 7.1.2.

Affected products

  • Tyche Softwares Print Invoice & Delivery Notes for WooCommerce <= 7.1.1

Timeline

  • 2026-04-27: other: Reported by Jakub Herman
  • 2026-06-25: advisory: Patchstack advisory published
  • 2026-06-26: disclosed: NVD publication date
  • 7.1.2: patched: Vulnerability fixed in version 7.1.2

References