Directory Traversal Vulnerability in WebToffee WooCommerce PDF Invoices Plugin
CVE-2026-18027

6.5MEDIUM

What is CVE-2026-18027?

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress features a directory traversal flaw that impacts all versions up to and including 4.9.8. This vulnerability allows authenticated attackers, with subscriber-level access or higher, to read arbitrary files on the server. Sensitive information may be disclosed as attackers can exploit the get_image_src_in_base64 function. The compromised file contents are encoded in base64 and subsequently served to the attacker through the plugin's Print/Download invoice endpoints, which require only a valid nonce and access key—exposing critical data without sufficient authentication controls.

Affected Version(s)

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels 0 <= 4.9.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.