WP Security CheckVulnerability data as of October 11, 2026

Vulnerability alerts / October 10, 2026

Vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels — CVE-2026-93746

HighSeverity
CVSS 7.5
0.5%Estimated exploit probability
EPSS
50,000+ sitesInstalls
5.0.3Fixed in

What to do now

Update WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels to 5.0.3 or later.

Affected versions

  • Everything up to and including 5.0.2

Affected: WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels (plugin, print-invoices-packing-slip-labels-for-woocommerce)

Check: The plugin on wordpress.org / Our record for WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels

What the vulnerability is

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents when the attacker-supplied (base64-encoded) 'email' equals the order's billing email — a non-secret identifier — instead of requiring the WooCommerce order_key. This makes it possible for unauthenticated attackers, when the site is configured to allow guest access to documents ('wt_pklist_print_button_access_for' != 'logged_in'), to retrieve any other customer's invoice, packing slip, delivery note, dispatch label or shipping label — including customer name, billing/shipping address, phone number, purchased products, prices, taxes and invoice metadata — by knowing the target order ID and the associated billing email address.

This description is reproduced verbatim from the public vulnerability record.

Sources

See other alerts