PDF Invoices & Packing Slips for WooCommerce <= 5.16.3 - Authenticated (Subscriber+) Missing Authorization to Order Information Disclosure via Document Number Preview

Medium 4.3 CWE-862Fixed in 5.16.4
ID
WPSEC-2026-0740
Plugin
PDF Invoices & Packing Slips for WooCommerce (woocommerce-pdf-invoices-packing-slips)
Affected
all versions before 5.16.4
Remediation
Update to 5.16.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
PDF Invoices & Packing Slips for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data via the wpo_wcpdf_preview_formatted_number AJAX action in all versions up to, and including, 5.16.3, due to a missing capability check in the ajax_preview_formatted_number() function, which only verifies a nonce that is also handed to logged-in customers in their My Account document links. This makes it possible for authenticated attackers, with Subscriber-level access and above, to load arbitrary orders by ID and retrieve their order number and the order and document dates through the number format placeholders.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0