Junglewise Threat Intelligence

CVE-2026-8611: Klamra Paycal for Aspaclaria IDOR in invoice_id parameter

CVE-2026-8611 · Severity: medium · CVSS 4.3 · Published 2026-06-06

Executive brief

The Klamra Paycal for Aspaclaria plugin for WordPress, which manages payment and invoicing features, contains a security flaw that allows logged-in users to view other customers' private invoices. By simply changing a number in the web address, an attacker can access sensitive personal information such as full names, email addresses, phone numbers, and purchase history. This could lead to significant privacy breaches and reputational damage for businesses using the plugin.

Technical details

The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability due to missing validation on the 'invoice_id' parameter. This flaw exists in the invoice download and rendering components, specifically within the 'download.php' and 'render.php' files. An authenticated attacker with at least subscriber-level permissions can exploit this by enumerating sequential post IDs to download invoices belonging to other customers. Successful exploitation results in the exposure of sensitive billing PII, including names, contact details, and order specifics. The issue is present in all versions up to and including 1.1.4.

Affected products

  • Klamra Klamra Paycal for Aspaclaria up to, and including, 1.1.4

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: advisory

References