Description
The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler (woocommerce-pdf-invoice-ajax.php:513), registered on wp_ajax_rednao_wcpdfinv_inspect_order, performing no capability check and no nonce verification before loading an arbitrary order by the attacker-supplied 'OrderNumber' POST field and serializing its full WC_Order::get_data() and meta to the response. This makes it possible for authenticated attackers with Subscriber-level access and above to read every WooCommerce order on the site — including billing/shipping address, email, phone number, payment method, gateway transaction ID, and order totals — by iterating order IDs.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Order Information Disclosure
Action: Patch
AI Analysis

Impact

The Woo PDF Invoice Builder plugin is vulnerable to an Insecure Direct Object Reference because the wp_ajax_rednao_wcpdfinv_inspect_order handler performs no capability check or nonce verification before loading any order specified by the attacker-supplied OrderNumber. This allows an authenticated user with Subscriber role or higher to read the full data for any WooCommerce order, exposing billing and shipping addresses, email, phone, payment method, gateway transaction ID, and totals. The flaw is an example of CWE-862, invalid access control leading to confidentiality compromise.

Affected Systems

The vulnerability affects the Woo PDF Invoice Builder plugin distributed by edgarrojas as "PDF Builder for WooCommerce" and applies to all releases up to and including version 2.0.8 on WordPress sites.

Risk and Exploitability

The CVSS base score is 6.5, indicating medium severity. An EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to be logged in with a Subscriber or higher role; the attacker can then repeatedly invoke the exposed AJAX endpoint with consecutive OrderNumber values to enumerate and disclose all orders.

Generated by OpenCVE AI on September 11, 2026 at 05:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Woo PDF Invoice Builder plugin to the latest release available on the WordPress repository, ensuring it is newer than version 2.0.8 and that the attacker is no longer able to call the vulnerable endpoint.
  • Verify or patch the plugin code so that the wp_ajax_rednao_wcpdfinv_inspect_order handler access to administrators—and requires a nonce to validate the request.
  • If an immediate update is not possible, disable or remove the plugin, or restrict the Subscriber role's ability to access order data through configuration or a security plugin that blocks the vulnerable AJAX route.

Generated by OpenCVE AI on September 11, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Edgarrojas
Edgarrojas pdf Builder For Woocommerce. Create Invoices,packing Slips And More
Wordpress
Wordpress wordpress
Vendors & Products Edgarrojas
Edgarrojas pdf Builder For Woocommerce. Create Invoices,packing Slips And More
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler (woocommerce-pdf-invoice-ajax.php:513), registered on wp_ajax_rednao_wcpdfinv_inspect_order, performing no capability check and no nonce verification before loading an arbitrary order by the attacker-supplied 'OrderNumber' POST field and serializing its full WC_Order::get_data() and meta to the response. This makes it possible for authenticated attackers with Subscriber-level access and above to read every WooCommerce order on the site — including billing/shipping address, email, phone number, payment method, gateway transaction ID, and order totals — by iterating order IDs.
Title Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Edgarrojas Pdf Builder For Woocommerce. Create Invoices,packing Slips And More
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:12.583Z

Reserved: 2026-06-07T11:13:24.812Z

Link: CVE-2026-11496

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:19.807

Modified: 2026-09-11T21:17:08.230

Link: CVE-2026-11496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:08Z

Weaknesses