Impact
The vulnerability is an insecure direct object reference in the WebToffee WooCommerce PDF Invoices plugin. Attackers can supply a base64‑encoded email that matches the order’s billing email. When guest access to documents is enabled, the plugin authorizes the request without any order key or authentication, allowing the attacker to download any printable order document for that order ID. The attacker learns billing or shipping address, phone number, product purchase details, prices, taxes and invoice metadata.
Affected Systems
Affected systems include the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress, versions up to and including 5.0.2. Sites with guest document access enabled (wt_pklist_print_button_access_for setting != logged_in) are vulnerable. The vulnerability exists in the handler defined in class-wf-woocommerce-packing-list-admin.php around lines 1127‑1149.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score is not available. In the absence of a KEV listing, it is considered not known to be exploited in the wild, but the vulnerability permits unauthenticated access to highly sensitive data. Attackers need only the order ID and billing email, both of which can be guessed or exposed in some environments. The weakness is a CWE‑639 Insecure Direct Object Reference that can lead to privilege escalation of data exposure without authentication.
OpenCVE Enrichment