Title: Security Vulnerability
Last modified: August 30, 2016

---

# Security Vulnerability

 *  Resolved [rsm40](https://wordpress.org/support/users/rsm40/)
 * (@rsm40)
 * [10 years, 10 months ago](https://wordpress.org/support/topic/security-vulnerability-9/)
 * Hi,
    Anybody that understands the url structure of this plugin can print invoices
   that do not belong to them or without being logged in. Lets say I submit my order
   and the print url for my invoice is: [http://www.example.com/index.php/my-account/print/1123/](http://www.example.com/index.php/my-account/print/1123/)
 * I can then deduce that there is a previous order with the No 1122
    [http://www.example.com/index.php/my-account/print/1122/](http://www.example.com/index.php/my-account/print/1122/)
   And without even being logged in I can print that order invoice. Then i can random
   guess every order with a 4 digit number and print all the invoices. I consider
   this a deal Breaker for the 30,000 + installs. Hope you can fix it.
 * [https://wordpress.org/plugins/woocommerce-delivery-notes/](https://wordpress.org/plugins/woocommerce-delivery-notes/)

Viewing 4 replies - 1 through 4 (of 4 total)

 *  [smelsworst](https://wordpress.org/support/users/smelsworst/)
 * (@smelsworst)
 * [10 years, 10 months ago](https://wordpress.org/support/topic/security-vulnerability-9/#post-6590567)
 * This is a SIGNIFICANT vulnerability as it violates privacy laws. Please advise
   of expected timeframe for a fix.
 *  [otto.radics](https://wordpress.org/support/users/ottoradics/)
 * (@ottoradics)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/security-vulnerability-9/#post-6590790)
 * I created a pull request for this, you can find it here: [https://github.com/piffpaffpuff/woocommerce-delivery-notes/pull/119](https://github.com/piffpaffpuff/woocommerce-delivery-notes/pull/119)
 *  [Halyra](https://wordpress.org/support/users/harasse/)
 * (@harasse)
 * [10 years, 9 months ago](https://wordpress.org/support/topic/security-vulnerability-9/#post-6590791)
 * Not so easy to do that it seems.
    When connected, you have access only to your
   own orders. When not connected, Url in mails contains # of the order (not necessarily
   sequential and contiguous) + the email of the order owner (not public).
 *  [David Mosterd](https://wordpress.org/support/users/davidmosterd/)
 * (@davidmosterd)
 * [10 years, 8 months ago](https://wordpress.org/support/topic/security-vulnerability-9/#post-6590803)
 * I think this should be marked as resolved?
 * Only when you add an email address to the link you can see the order. [@harasse](https://wordpress.org/support/users/harasse/)
   also noted this.

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Security Vulnerability’ is closed to new replies.

 * ![](https://ps.w.org/woocommerce-delivery-notes/assets/icon-256x256.jpg?rev=2829362)
 * [Print Invoice & Delivery Notes for WooCommerce](https://wordpress.org/plugins/woocommerce-delivery-notes/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/woocommerce-delivery-notes/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/woocommerce-delivery-notes/)
 * [Active Topics](https://wordpress.org/support/plugin/woocommerce-delivery-notes/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/woocommerce-delivery-notes/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/woocommerce-delivery-notes/reviews/)

 * 4 replies
 * 5 participants
 * Last reply from: [David Mosterd](https://wordpress.org/support/users/davidmosterd/)
 * Last activity: [10 years, 8 months ago](https://wordpress.org/support/topic/security-vulnerability-9/#post-6590803)
 * Status: resolved