Description
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve invoice numbers, formatted invoice numbers, and creation timestamps for arbitrary WooCommerce orders by supplying any OrderNumber and InvoiceId values with a garbage nonce.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive invoice data disclosure
Action: Immediate Patch
AI Analysis

Impact

The PDF Builder for WooCommerce plugin is vulnerable to an instance of CWE-862, the Authorization Bypass Through User‑Controlled Key, that allows authenticated users with subscriber-level access or higher to retrieve detailed invoice information. An attacker can supply arbitrary OrderNumber and InvoiceId values along with a non‑existent nonce to trigger an AJAX handler that returns the invoice number, a formatted invoice number, and the order creation timestamp. This results in a confidentiality breach, exposing sensitive transactional data to attackers who are already authenticated but not intended to view other customers’ invoices.

Affected Systems

WordPress sites that have the "PDF Builder for WooCommerce. Create invoices, packing slips and more" plugin installed, version 2.0.11 or earlier. The vulnerability is present in all up to and including 2.0.11 and requires that the site has WooCommerce enabled and an order system in place.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, but the EPSS score of less than 1% shows that current worldwide exploitation probability is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated with at least subscriber privileges and must construct a valid AJAX request, which is relatively trivial with knowledge of the endpoint. Once executed, the gains read‑only access to invoice details for any order on the site, compromising privacy and potentially aiding fraud investigations.

Generated by OpenCVE AI on September 20, 2026 at 00:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the PDF Builder for WooCommerce plugin to version 2.0.12 or newer, where the AJAX handler validates the nonce and enforces proper authorization checks.
  • Restrict the woocommerce‑pdf‑invoice‑ajax.php endpoint to users with elevated capabilities (e.g., editors or administrators) by applying role‑based access controls or server‑side route restrictions.
  • Ensure that the nonce verification routine is active; if it is missing, insert a check that confirms the provided nonce matches the WordPress session nonce before processing invoice data.

Generated by OpenCVE AI on September 20, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Edgarrojas
Edgarrojas pdf Builder For Woocommerce. Create Invoices,packing Slips And More
Wordpress
Wordpress wordpress
Vendors & Products Edgarrojas
Edgarrojas pdf Builder For Woocommerce. Create Invoices,packing Slips And More
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve invoice numbers, formatted invoice numbers, and creation timestamps for arbitrary WooCommerce orders by supplying any OrderNumber and InvoiceId values with a garbage nonce.
Title PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Edgarrojas Pdf Builder For Woocommerce. Create Invoices,packing Slips And More
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:24.886Z

Reserved: 2026-06-10T15:41:44.961Z

Link: CVE-2026-11899

cve-icon Vulnrichment

Updated: 2026-09-19T13:55:11.462Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:51.760

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-11899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:30:13Z

Weaknesses