Description
Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.150.
Published: 2025-11-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the WooCommerce PDF Invoice Builder plugin allows an attacker who can access the site’s invoice generation URLs to download PDF invoices without proper authentication. The flaw resides in incorrectly configured access control security levels, reducing the confidentiality of customer order information. The vulnerability is classified as CWE-862 and can potentially expose sensitive payment and customer data to non‑privileged users.

Affected Systems

The flaw affects all installations of the WooCommerce PDF Invoice Builder plugin by Edgar Rojas, from the earliest release through version 1.2.150. Users running any of these versions are susceptible if the plugin is enabled and accessible via the WordPress admin or frontend interface.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests that widespread exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an unauthenticated user can request the invoice URLs exposed by the plugin, as the access control check is missing. An attacker does not need elevated privileges, and therefore the scope of impact may extend to all customers whose invoices are generated through the plugin.

Generated by OpenCVE AI on April 29, 2026 at 20:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WooCommerce PDF Invoice Builder plugin to a version newer than 1.2.150 if a release is available that fixes the authorization issue.
  • If no update is available, restrict direct access to the invoice generation endpoints by applying role‑based access control or server‑level restrictions such as .htaccess rules to allow only authenticated users with appropriate permissions.
  • Disable the plugin as a temporary measure until an official patch is applied, or remove the invoice generation capability from the front‑end if it is not required for your business processes.

Generated by OpenCVE AI on April 29, 2026 at 20:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Edgarrojas
Edgarrojas woocommerce Pdf Invoice Builder
Wordpress
Wordpress wordpress
Vendors & Products Edgarrojas
Edgarrojas woocommerce Pdf Invoice Builder
Wordpress
Wordpress wordpress

Thu, 13 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.150.
Title WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Edgarrojas Woocommerce Pdf Invoice Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:13.326Z

Reserved: 2025-10-29T03:08:27.751Z

Link: CVE-2025-64269

cve-icon Vulnrichment

Updated: 2025-11-13T17:57:24.439Z

cve-icon NVD

Status : Deferred

Published: 2025-11-13T10:15:52.260

Modified: 2026-04-27T16:16:39.153

Link: CVE-2025-64269

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:15:19Z

Weaknesses