{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/woocommerce-pdf-invoices-packing-slips-delivery-notes--shipping-labels--5.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:webtoffee:woocommerce_pdf_invoices_packing_slips_delivery_notes_shipping_labels:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93746"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WooCommerce PDF Invoices, Packing Slips, Delivery Notes \u0026 Shipping Labels (\u003c= 5.0.2)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","idor","wordpress"],"_cs_type":"advisory","_cs_vendors":["WebToffee"],"content_html":"\u003cp\u003eThe WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes \u0026amp; Shipping Labels plugin for WordPress (versions 5.0.2 and earlier) contains an Insecure Direct Object Reference (IDOR) vulnerability. The vulnerability resides in the \u003ccode\u003eprint_document_from_the_mail_link\u003c/code\u003e handler, which is triggered when \u003ccode\u003eprint_window()\u003c/code\u003e is called during the \u003ccode\u003einit\u003c/code\u003e hook. When a site is configured to permit guest access to printable documents, the plugin fails to validate requests against the secure \u003ccode\u003eorder_key\u003c/code\u003e. Instead, it authorizes document retrieval based solely on the \u003ccode\u003eemail\u003c/code\u003e parameter. If an attacker provides a base64-encoded email address that matches the billing email of an order, the server returns the requested document. This allows unauthenticated actors to access sensitive data, including customer names, billing and shipping addresses, phone numbers, purchased product lists, tax information, and order metadata.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to exfiltrate private customer order information at scale, provided they possess a valid order ID and the associated billing email address. This results in the unauthorized disclosure of personally identifiable information (PII) and financial transaction details, potentially impacting a large customer base for any affected e-commerce store.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes \u0026amp; Shipping Labels plugin to version 5.0.3 or later immediately to patch CVE-2026-93746.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous, high-volume requests to WordPress endpoints associated with document printing functionality (e.g., URLs containing \u003ccode\u003eprint_document_from_the_mail_link\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eConfigure the plugin settings to restrict document access to logged-in users only, setting \u003ccode\u003ewt_pklist_print_button_access_for\u003c/code\u003e to \u003ccode\u003elogged_in\u003c/code\u003e as a temporary mitigation until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T09:51:41Z","date_published":"2026-10-10T09:51:41Z","id":"https://feed.craftedsignal.io/briefs/2026-10-webtoffee-idor/","summary":"An unauthenticated IDOR vulnerability in the WebToffee WooCommerce PDF Invoices plugin allows attackers to retrieve sensitive customer order documents by supplying a known email address.","title":"Unauthenticated IDOR Vulnerability in WebToffee WooCommerce Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-webtoffee-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - WooCommerce PDF Invoices, Packing Slips, Delivery Notes \u0026 Shipping Labels (\u003c= 5.0.2)","version":"https://jsonfeed.org/version/1.1"}