Executive brief
The Woo PDF Invoice Builder WordPress plugin fails to properly protect access to order information in its inspection feature. An authenticated attacker with basic user privileges can retrieve sensitive order details—including customer names, addresses, email, phone numbers, and payment information—for any order on the site by guessing or iterating order IDs, exposing customer data and potentially enabling further attacks.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the InspectOrder() AJAX handler (registered as wp_ajax_rednao_wcpdfinv_inspect_order) within woocommerce-pdf-invoice-ajax.php at line 513. The handler accepts an attacker-supplied 'OrderNumber' POST parameter and loads the corresponding WC_Order without performing capability checks or nonce verification. It then serializes the complete order data and metadata (WC_Order::get_data()) to the response. Attack requires only network access and valid WordPress authentication as a Subscriber or higher; no admin access is needed. An attacker can iterate order IDs to enumerate and extract all orders on the site, including PII and payment details. The vulnerability affects all versions up to and including 2.0.8.
Affected products
- WooThemes Woo PDF Invoice Builder up to 2.0.8
Timeline
- 2026-09-11: disclosed