Directory Traversal Vulnerability in WebToffee WooCommerce PDF Invoices Plugin
CVE-2026-18027
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 August 2026
What is CVE-2026-18027?
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress features a directory traversal flaw that impacts all versions up to and including 4.9.8. This vulnerability allows authenticated attackers, with subscriber-level access or higher, to read arbitrary files on the server. Sensitive information may be disclosed as attackers can exploit the get_image_src_in_base64 function. The compromised file contents are encoded in base64 and subsequently served to the attacker through the plugin's Print/Download invoice endpoints, which require only a valid nonce and access key—exposing critical data without sufficient authentication controls.
Affected Version(s)
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels 0 <= 4.9.8