<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WebToffee - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/webtoffee/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:51:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/webtoffee/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated IDOR Vulnerability in WebToffee WooCommerce Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-webtoffee-idor/</link><pubDate>Sat, 10 Oct 2026 09:51:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-webtoffee-idor/</guid><description>An unauthenticated IDOR vulnerability in the WebToffee WooCommerce PDF Invoices plugin allows attackers to retrieve sensitive customer order documents by supplying a known email address.</description><content:encoded><![CDATA[<p>The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes &amp; Shipping Labels plugin for WordPress (versions 5.0.2 and earlier) contains an Insecure Direct Object Reference (IDOR) vulnerability. The vulnerability resides in the <code>print_document_from_the_mail_link</code> handler, which is triggered when <code>print_window()</code> is called during the <code>init</code> hook. When a site is configured to permit guest access to printable documents, the plugin fails to validate requests against the secure <code>order_key</code>. Instead, it authorizes document retrieval based solely on the <code>email</code> parameter. If an attacker provides a base64-encoded email address that matches the billing email of an order, the server returns the requested document. This allows unauthenticated actors to access sensitive data, including customer names, billing and shipping addresses, phone numbers, purchased product lists, tax information, and order metadata.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to exfiltrate private customer order information at scale, provided they possess a valid order ID and the associated billing email address. This results in the unauthorized disclosure of personally identifiable information (PII) and financial transaction details, potentially impacting a large customer base for any affected e-commerce store.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes &amp; Shipping Labels plugin to version 5.0.3 or later immediately to patch CVE-2026-93746.</li>
<li>Audit web server access logs for anomalous, high-volume requests to WordPress endpoints associated with document printing functionality (e.g., URLs containing <code>print_document_from_the_mail_link</code>).</li>
<li>Configure the plugin settings to restrict document access to logged-in users only, setting <code>wt_pklist_print_button_access_for</code> to <code>logged_in</code> as a temporary mitigation until the patch is applied.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>idor</category><category>wordpress</category></item></channel></rss>