Executive brief
A vulnerability in the WhatsOrder plugin for WordPress allows unauthorized individuals to access and download customer invoices. This exposure includes sensitive personal information such as names, email addresses, phone numbers, and physical addresses, as well as order details and pricing. An attacker can systematically download these documents because they are stored in a public folder without proper security protections.
Technical details
The WhatsOrder plugin fails to implement proper access controls or directory protection for generated invoice files. Specifically, the 'yapacdev_generate_order_pdf' function writes invoice HTML files to a publicly accessible directory (wp-content/uploads/whatsorder_invoices/) that lacks an .htaccess deny rule or an index.php guard. An unauthenticated remote attacker can exploit this by enumerating sequential order IDs to guess the filenames and directly download invoices over HTTP. This results in the exposure of sensitive customer PII, including full names, contact details, billing addresses, and full order histories.
Affected products
- yapacdev WhatsOrder – Instant Checkout for WooCommerce up to, and including, 1.0.1
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/whatsorder-instant-checkout-for-woocommerce/tags/1.0.0/whatsorder-instant-checkout-for-woocommerce.php
- https://plugins.trac.wordpress.org/browser/whatsorder-instant-checkout-for-woocommerce/tags/1.0.0/whatsorder-instant-checkout-for-woocommerce.php
- https://plugins.trac.wordpress.org/browser/whatsorder-instant-checkout-for-woocommerce/tags/1.0.0/whatsorder-instant-checkout-for-woocommerce.php
- https://plugins.trac.wordpress.org/browser/whatsorder-instant-checkout-for-woocommerce/tags/1.0.1/whatsorder-instant-checkout-for-woocommerce.php
- https://plugins.trac.wordpress.org/browser/whatsorder-instant-checkout-for-woocommerce/tags/1.0.1/whatsorder-instant-checkout-for-woocommerce.php
- https://plugins.trac.wordpress.org/browser/whatsorder-instant-checkout-for-woocommerce/tags/1.0.1/whatsorder-instant-checkout-for-woocommerce.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e5d625d6-57e0-4dc7-b3ee-cb0639a02230?source=cve