Junglewise Threat Intelligence

CVE-2026-49056: WebToffee WooCommerce PDF Invoices sensitive data exposure

CVE-2026-49056 · Severity: high · CVSS 7.5 · Published 2026-06-15

Vendors: WebToffee.

Executive brief

A vulnerability in a popular WordPress plugin used for generating e-commerce documents allows unauthorized individuals to access sensitive information. This plugin is typically used to create invoices, packing slips, and shipping labels for online stores. An attacker could exploit this flaw to view private customer or order data, potentially leading to privacy violations and further targeted attacks against the business or its customers.

Technical details

The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthenticated sensitive data exposure (CWE-497) in versions up to and including 4.9.4. The flaw allows a remote attacker to access sensitive system or transaction information without requiring any prior authentication or user interaction. This is likely due to insufficient access controls on generated documents or plugin-specific endpoints. An attacker can leverage this to harvest data that should be restricted to site administrators or specific customers. The issue is resolved in version 4.9.5.

Affected products

  • WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4

Timeline

  • 2026-04-27: other: Vulnerability reported by Jakub Herman
  • 2026-06-03: disclosed: Initial disclosure by Patchstack
  • 2026-06-15: advisory: NVD publication date

References