CVE · High

CVE-2026-49056 — WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.9.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-49056 WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.9.5 Exposure of Sensitive System Information to an Unauthorized Control Sphere High 7.5 < 4.9.5 4.9.5 2026-06-03

CVE-2026-49056

All versions of the WebToffee WooCommerce PDF Invoices plugin prior to version 5 are susceptible to a security flaw that allows unauthorized individuals to access confidential user details and configuration settings without requiring authentication. This vulnerability is present in every edition up to, but not including, version 4.9.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.