CVE Database /
CVE-2026-13116
CVE · Medium
CVE-2026-13116 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-13116
|
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 5.15.0
|
5.15.0 |
2026-07-10 |
—
|
CVE-2026-13116
A vulnerability exists in the PDF Invoices & Packing Slips for WooCommerce plugin due to inadequate validation of user-controlled input. This allows authenticated users with contributor-level access or higher to create public links to download arbitrary orders' invoices and packing slips, exposing sensitive customer information. The vulnerability is triggered when the plugin's Document link access type is set to "full", allowing attackers to bypass session-based access controls and obtain unauthorized access to orders.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings