CVE · Medium

CVE-2026-13116 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13116 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0 Authorization Bypass Through User-Controlled Key Medium 4.3 < 5.15.0 5.15.0 2026-07-10

CVE-2026-13116

A vulnerability exists in the PDF Invoices & Packing Slips for WooCommerce plugin due to inadequate validation of user-controlled input. This allows authenticated users with contributor-level access or higher to create public links to download arbitrary orders' invoices and packing slips, exposing sensitive customer information. The vulnerability is triggered when the plugin's Document link access type is set to "full", allowing attackers to bypass session-based access controls and obtain unauthorized access to orders.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.