Impact
The Woo PDF Invoice Builder plugin is vulnerable to an Insecure Direct Object Reference because the wp_ajax_rednao_wcpdfinv_inspect_order handler performs no capability check or nonce verification before loading any order specified by the attacker-supplied OrderNumber. This allows an authenticated user with Subscriber role or higher to read the full data for any WooCommerce order, exposing billing and shipping addresses, email, phone, payment method, gateway transaction ID, and totals. The flaw is an example of CWE-862, invalid access control leading to confidentiality compromise.
Affected Systems
The vulnerability affects the Woo PDF Invoice Builder plugin distributed by edgarrojas as "PDF Builder for WooCommerce" and applies to all releases up to and including version 2.0.8 on WordPress sites.
Risk and Exploitability
The CVSS base score is 6.5, indicating medium severity. An EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to be logged in with a Subscriber or higher role; the attacker can then repeatedly invoke the exposed AJAX endpoint with consecutive OrderNumber values to enumerate and disclose all orders.
OpenCVE Enrichment