Unauthenticated IDOR Vulnerability in WebToffee WooCommerce Plugin
An unauthenticated IDOR vulnerability in the WebToffee WooCommerce PDF Invoices plugin allows attackers to retrieve sensitive customer order documents by supplying a known email address.
CVE search metadata
CVE search record: CVE-2026-93746. Severity: high. CVSS: 7.5. KEV: no. Product: WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels (<= 5.0.2). Brief: Unauthenticated IDOR Vulnerability in WebToffee WooCommerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-webtoffee-idor/
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress (versions 5.0.2 and earlier) contains an Insecure Direct Object Reference (IDOR) vulnerability. The vulnerability resides in the print_document_from_the_mail_link handler, which is triggered when print_window() is called during the init hook. When a site is configured to permit guest access to printable documents, the plugin fails to validate requests against the secure order_key. Instead, it authorizes document retrieval based solely on the email parameter. If an attacker provides a base64-encoded email address that matches the billing email of an order, the server returns the requested document. This allows unauthenticated actors to access sensitive data, including customer names, billing and shipping addresses, phone numbers, purchased product lists, tax information, and order metadata.
Impact
Successful exploitation allows unauthenticated attackers to exfiltrate private customer order information at scale, provided they possess a valid order ID and the associated billing email address. This results in the unauthorized disclosure of personally identifiable information (PII) and financial transaction details, potentially impacting a large customer base for any affected e-commerce store.
Recommendation
- Upgrade the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin to version 5.0.3 or later immediately to patch CVE-2026-93746.
- Audit web server access logs for anomalous, high-volume requests to WordPress endpoints associated with document printing functionality (e.g., URLs containing
print_document_from_the_mail_link). - Configure the plugin settings to restrict document access to logged-in users only, setting
wt_pklist_print_button_access_fortologged_inas a temporary mitigation until the patch is applied.
Immediate actions
Upgrade WebToffee WooCommerce plugin to version 5.0.3 or later
Mitigations
Set wt_pklist_print_button_access_for to logged_in in plugin settings
CVE-2026-93746