Description
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents when the attacker-supplied (base64-encoded) 'email' equals the order's billing email — a non-secret identifier — instead of requiring the WooCommerce order_key. This makes it possible for unauthenticated attackers, when the site is configured to allow guest access to documents ('wt_pklist_print_button_access_for' != 'logged_in'), to retrieve any other customer's invoice, packing slip, delivery note, dispatch label or shipping label — including customer name, billing/shipping address, phone number, purchased products, prices, taxes and invoice metadata — by knowing the target order ID and the associated billing email address.
Published: 2026-10-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized access to order documents and sensitive customer information
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an insecure direct object reference in the WebToffee WooCommerce PDF Invoices plugin. Attackers can supply a base64‑encoded email that matches the order’s billing email. When guest access to documents is enabled, the plugin authorizes the request without any order key or authentication, allowing the attacker to download any printable order document for that order ID. The attacker learns billing or shipping address, phone number, product purchase details, prices, taxes and invoice metadata.

Affected Systems

Affected systems include the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress, versions up to and including 5.0.2. Sites with guest document access enabled (wt_pklist_print_button_access_for setting != logged_in) are vulnerable. The vulnerability exists in the handler defined in class-wf-woocommerce-packing-list-admin.php around lines 1127‑1149.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and the EPSS score is not available. In the absence of a KEV listing, it is considered not known to be exploited in the wild, but the vulnerability permits unauthenticated access to highly sensitive data. Attackers need only the order ID and billing email, both of which can be guessed or exposed in some environments. The weakness is a CWE‑639 Insecure Direct Object Reference that can lead to privilege escalation of data exposure without authentication.

Generated by OpenCVE AI on October 10, 2026 at 09:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest version of the WebToffee WooCommerce PDF Invoices plugin (5.0.3 or newer) to remove the insecure email handling.
  • Reconfigure the plugin to disable guest access to order documents by setting wt_pklist_print_button_access_for to "logged_in" until a fix is applied.
  • Restrict access to printable order documents by enforcing the requirement of the WooCommerce order_key or implementing a custom access control check.

Generated by OpenCVE AI on October 10, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents when the attacker-supplied (base64-encoded) 'email' equals the order's billing email — a non-secret identifier — instead of requiring the WooCommerce order_key. This makes it possible for unauthenticated attackers, when the site is configured to allow guest access to documents ('wt_pklist_print_button_access_for' != 'logged_in'), to retrieve any other customer's invoice, packing slip, delivery note, dispatch label or shipping label — including customer name, billing/shipping address, phone number, purchased products, prices, taxes and invoice metadata — by knowing the target order ID and the associated billing email address.
Title WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 5.0.2 - Insecure Direct Object Reference to Unauthenticated Unauthorized Order Document Access via 'email' Parameter
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:48.536Z

Reserved: 2026-09-18T16:07:05.185Z

Link: CVE-2026-93746

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:04.907

Modified: 2026-10-10T08:17:04.907

Link: CVE-2026-93746

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key