Impact
Insecure Direct Object Reference via the generate_document_shortcode allows an authenticated contributor or higher to construct session‑free download links for arbitrary orders when the plugin’s Document link access type is set to 'full'. This flaw, classified as CWE‑639, can expose customer information such as names, addresses, email, phone, order IDs, invoices, items, totals, payment details, and notes contained in the PDFs. The vulnerability arises from missing validation on a user‑controlled key within the shortcode attribute.
Affected Systems
All releases of the PDF Invoices & Packing Slips for WooCommerce plugin from wpovernight up to and including version 5.14.0 are affected. Sites running any of these versions on WordPress with the Document link access type configured to 'full' are at risk. The default configuration uses a per‑session nonce and mitigates the issue, but the misconfiguration makes the vulnerability exploitable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated role of contributor or higher and the presence of the 'full' access type setting; other user roles or the default 'logged_in' configuration prevent unauthorized access. Attackers would gain information disclosure, as documented.
OpenCVE Enrichment