Impact
The WooCommerce PDF Invoice Builder plugin by EDGARROJAS includes a flaw that permits an attacker to perform a CSRF attack. The flaw allows an authenticated user to unknowingly trigger the plugin to generate or manipulate PDF invoices. If exploited, an attacker could create invoices or export financial documents, potentially exposing sensitive order data. The issue is identified as CWE‑352 and carries a CVSS score of 4.3, indicating a moderate risk level.
Affected Systems
The vulnerability affects the WooCommerce PDF Invoice Builder plugin by EDGARROJAS in all releases up to and including version 1.2.148. No specific sub‑versions are listed beyond the upper bound, so any installed instance with a version number less than or equal to 1.2.148 is considered vulnerable.
Risk and Exploitability
Although the EPSS score is less than 1 %, meaning exploitation is unlikely at present, the vulnerability is still exploitable when a logged‑in user is tricked into visiting a malicious URL. The attacker requires no additional privileges; the CSRF token validation is insufficient. The flaw is not listed in the CISA KEV catalog, but due to its moderate CVSS score and potential for data exposure, it warrants immediate attention.
OpenCVE Enrichment
EUVD