What the vulnerability does
01Description
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.
Explanation of Vulnerability in Simple Terms
02Summary
PDF Builder for WooCommerce versions up to 1.2.91 lack proper authorization checks, allowing authenticated users to access sensitive information they should not be able to view. An attacker with a low-privilege account can read data intended for other users or roles. Update to a version newer than 1.2.91 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive data (invoices, packing slips, customer information) belonging to other users or orders.
Potential impact on your site
04Site Impact
Customer data and order information may be exposed to unauthorized users with site access.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WooCommerce user account with at least low-level privileges.
Key dates
06Disclosure timeline
August 31, 2023
CVE published
April 8, 2026
Record updated