Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtoffee
Webtoffee woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels Wordpress Wordpress wordpress |
|
| Vendors & Products |
Webtoffee
Webtoffee woocommerce Pdf Invoices, Packing Slips, Delivery Notes And Shipping Labels Wordpress Wordpress wordpress |
Mon, 24 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 22 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The base64-encoded file contents are embedded into the cached invoice HTML and served directly to the attacker via the plugin's own Print/Download invoice endpoints, which require only a valid nonce and access key. | |
| Title | WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-24T13:01:19.729Z
Reserved: 2026-07-28T05:50:17.888Z
Link: CVE-2026-18027
Updated: 2026-08-24T12:51:26.596Z
Status : Deferred
Published: 2026-08-23T00:16:50.370
Modified: 2026-08-24T16:41:13.950
Link: CVE-2026-18027
No data.
OpenCVE Enrichment
Updated: 2026-08-24T21:00:12Z