Impact
The WooCommerce PDF Invoice Builder plugin contains a flaw that allows an unauthenticated user to retrieve embedded sensitive data from invoices generated by the plugin. The vulnerability is classified as CWE‑497, which indicates incorrect provisioning of sensitive information. An exploited instance could expose confidential data such as order details or customer information, representing a moderate confidentiality breach.
Affected Systems
The flaw affects the EDGARROJAS WooCommerce PDF Invoice Builder WordPress plugin for all releases up to and including version 2.0.8. Any site that has installed the plugin at version 2.0.8 or older is at risk.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate overall severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation in the near term is very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers can likely exploit the issue remotely via web requests to the plugin’s endpoints, but the flaw does not provide code execution or privilege escalation.
OpenCVE Enrichment