Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WooCommerce PDF Invoice Builder plugin contains a flaw that allows an unauthenticated user to retrieve embedded sensitive data from invoices generated by the plugin. The vulnerability is classified as CWE‑497, which indicates incorrect provisioning of sensitive information. An exploited instance could expose confidential data such as order details or customer information, representing a moderate confidentiality breach.

Affected Systems

The flaw affects the EDGARROJAS WooCommerce PDF Invoice Builder WordPress plugin for all releases up to and including version 2.0.8. Any site that has installed the plugin at version 2.0.8 or older is at risk.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate overall severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation in the near term is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can likely exploit the issue remotely via web requests to the plugin’s endpoints, but the flaw does not provide code execution or privilege escalation.

Generated by OpenCVE AI on July 31, 2026 at 12:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WooCommerce PDF Invoice Builder plugin to a version beyond 2.0.8 once available.
  • If a timely update cannot be applied, disable the plugin entirely to eliminate the exposure path.
  • Configure the plugin’s access controls so that only administrators can invoke its functionality, thereby reducing the attack surface.

Generated by OpenCVE AI on July 31, 2026 at 12:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Edgarrojas
Edgarrojas woocommerce Pdf Invoice Builder
Wordpress
Wordpress wordpress
Vendors & Products Edgarrojas
Edgarrojas woocommerce Pdf Invoice Builder
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.
Title WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Edgarrojas Woocommerce Pdf Invoice Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-21T16:56:54.582Z

Reserved: 2026-06-24T12:46:07.752Z

Link: CVE-2026-57393

cve-icon Vulnrichment

Updated: 2026-07-13T13:48:42.328Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere