Impact
The PDF Builder for WooCommerce plugin is vulnerable to an instance of CWE-862, the Authorization Bypass Through User‑Controlled Key, that allows authenticated users with subscriber-level access or higher to retrieve detailed invoice information. An attacker can supply arbitrary OrderNumber and InvoiceId values along with a non‑existent nonce to trigger an AJAX handler that returns the invoice number, a formatted invoice number, and the order creation timestamp. This results in a confidentiality breach, exposing sensitive transactional data to attackers who are already authenticated but not intended to view other customers’ invoices.
Affected Systems
WordPress sites that have the "PDF Builder for WooCommerce. Create invoices, packing slips and more" plugin installed, version 2.0.11 or earlier. The vulnerability is present in all up to and including 2.0.11 and requires that the site has WooCommerce enabled and an order system in place.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, but the EPSS score of less than 1% shows that current worldwide exploitation probability is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated with at least subscriber privileges and must construct a valid AJAX request, which is relatively trivial with knowledge of the endpoint. Once executed, the gains read‑only access to invoice details for any order on the site, compromising privacy and potentially aiding fraud investigations.
OpenCVE Enrichment