Sceawere

Vulnerability Detail

CVE-2026-93746UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IDOR Vulnerability in WebToffee WooCommerce PDF Invoices

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
webtoffee
Product
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents when the attacker-supplied (base64-encoded) 'email' equals the order's billing email — a non-secret identifier — instead of requiring the WooCommerce order_key. This makes it possible for unauthenticated attackers, when the site is configured to allow guest access to documents ('wt_pklist_print_button_access_for' != 'logged_in'), to retrieve any other customer's invoice, packing slip, delivery note, dispatch label or shipping label — including customer name, billing/shipping address, phone number, purchased products, prices, taxes and invoice metadata — by knowing the target order ID and the associated billing email address.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-10T08:17:04.907Z",
  "pubdate": "2026-10-10T08:17:04.907Z",
  "executiveSummary": "The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress, in versions up to and including 5.0.2, contains a critical Insecure Direct Object Reference (IDOR) vulnerability. The flaw resides within the guest print_document_from_the_mail_link handler triggered via the print_window() function.\nThis vulnerability allows unauthenticated attackers to bypass intended access controls and retrieve sensitive order documents, including invoices, packing slips, and shipping labels, by manipulating order ID parameters and the associated billing email address. The authorization logic fails to validate the request against the cryptographically secure order_key, relying instead on the base64-encoded email address—a non-secret identifier—to verify identity.\nExploitation is feasible if the site configuration permits guest access to documents. Successful exploitation exposes sensitive customer data, including full names, billing and shipping addresses, telephone numbers, order history, financial pricing data, and metadata. This poses significant risks to user privacy, regulatory compliance, and potential business operations. Organizations running affected versions are strongly advised to restrict public access to documents until a patch is applied.",
  "technicalDetails": "The vulnerability is rooted in the implementation of the print_document_from_the_mail_link handler, which is dispatched via the print_window() function on the init hook. The root cause is the flawed authorization mechanism used to verify user identity for guest document retrieval.\nWhen a user attempts to retrieve an order document, the plugin requires the target order ID and an 'email' parameter. The server-side logic takes the provided email, decodes the base64 string, and performs a direct comparison against the WooCommerce billing email associated with the specified order ID. Because the billing email is essentially public or easily discoverable information, it does not serve as a valid security token.\nThe intended authorization flow should mandate the usage of a cryptographically secure, high-entropy unique identifier, such as the WooCommerce order_key, which is specifically designed to protect against direct object access. By omitting this requirement, the plugin grants access to any document associated with an order ID as long as the requester knows the corresponding billing email.\nThe exploitation flow proceeds as follows: First, the attacker identifies a valid target order ID. Second, the attacker retrieves or guesses the billing email address associated with said order ID. Third, the attacker encodes the email in base64 format as expected by the handler. Fourth, the attacker crafts an HTTP request to the print_window() endpoint, supplying the order ID and the base64-encoded email. If the WordPress installation is configured with 'wt_pklist_print_button_access_for' set to allow guest access, the server validates the non-secret email match and returns the requested PDF document.\nThis behavior exposes the full scope of customer information stored within the documents, which includes Personally Identifiable Information (PII) such as full names, physical addresses, and contact numbers. Additionally, the documents contain sensitive transactional metadata including purchased products, line-item pricing, tax details, and historical invoicing data. Because the exploit occurs at the web application layer and requires no authentication, it is highly accessible to remote, unauthenticated threat actors over the public network."
}
CVE-2026-93746: IDOR Vulnerability in WebToffee WooCommerce PDF Invoices (HIGH Severity, CVSS: 7.5) | Sceawere