Executive brief
The WooCommerce PDF Invoice Builder plugin for WordPress, which automates the creation of invoices for online stores, contains a security flaw that exposes sensitive system information. An attacker with a basic user account could exploit this to view internal data that should be restricted. This information could potentially be used to facilitate further attacks against the website or its customers.
Technical details
A sensitive data exposure vulnerability (CWE-497) exists in the EDGARROJAS WooCommerce PDF Invoice Builder plugin through version 2.0.8. The flaw allows an authenticated attacker, specifically those with 'Subscriber' level privileges, to retrieve embedded sensitive system information that is normally restricted to higher-level administrators. This occurs due to improper control over the exposure of system-level data within the plugin's environment. The issue is resolved in version 2.0.9.
Affected products
- EDGARROJAS WooCommerce PDF Invoice Builder (woo-pdf-invoice-builder) <= 2.0.8
Timeline
- 2026-06-04: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-08: patched: Version 2.0.9 released to address the vulnerability
- 2026-07-13: advisory: NVD published the CVE record