Skip to content
Threat Feed
high advisory

Unauthenticated IDOR Vulnerability in WebToffee WooCommerce Plugin

An unauthenticated IDOR vulnerability in the WebToffee WooCommerce PDF Invoices plugin allows attackers to retrieve sensitive customer order documents by supplying a known email address.

CVE search metadata

CVE search record: CVE-2026-93746. Severity: high. CVSS: 7.5. KEV: no. Product: WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels (<= 5.0.2). Brief: Unauthenticated IDOR Vulnerability in WebToffee WooCommerce Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-webtoffee-idor/

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress (versions 5.0.2 and earlier) contains an Insecure Direct Object Reference (IDOR) vulnerability. The vulnerability resides in the print_document_from_the_mail_link handler, which is triggered when print_window() is called during the init hook. When a site is configured to permit guest access to printable documents, the plugin fails to validate requests against the secure order_key. Instead, it authorizes document retrieval based solely on the email parameter. If an attacker provides a base64-encoded email address that matches the billing email of an order, the server returns the requested document. This allows unauthenticated actors to access sensitive data, including customer names, billing and shipping addresses, phone numbers, purchased product lists, tax information, and order metadata.

Impact

Successful exploitation allows unauthenticated attackers to exfiltrate private customer order information at scale, provided they possess a valid order ID and the associated billing email address. This results in the unauthorized disclosure of personally identifiable information (PII) and financial transaction details, potentially impacting a large customer base for any affected e-commerce store.

Recommendation

  • Upgrade the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin to version 5.0.3 or later immediately to patch CVE-2026-93746.
  • Audit web server access logs for anomalous, high-volume requests to WordPress endpoints associated with document printing functionality (e.g., URLs containing print_document_from_the_mail_link).
  • Configure the plugin settings to restrict document access to logged-in users only, setting wt_pklist_print_button_access_for to logged_in as a temporary mitigation until the patch is applied.

Immediate actions

Upgrade WebToffee WooCommerce plugin to version 5.0.3 or later

IT Operations 24h

Mitigations

Set wt_pklist_print_button_access_for to logged_in in plugin settings

immediate IT Operations

CVE-2026-93746