CVE-2026-13116 Details
Description
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to mint publicly accessible, session-free download links for arbitrary third-party orders, exposing customer names, billing and shipping addresses, email addresses, phone numbers, order and invoice numbers, line items, totals, payment details, and customer notes contained in those orders' invoices and packing slips. Exploitation requires the plugin's Document link access type setting to be configured to 'full'; with the default 'logged_in' value, generated URLs are signed with a per-session nonce rather than the order_key, making the shortcode path unexploitable for unauthorized access to third-party orders.
A vulnerability exists in the PDF Invoices & Packing Slips for WooCommerce plugin for WordPress, in all versions through 5.14.0. The issue is an Insecure Direct Object Reference (IDOR) that allows authenticated attackers with contributor-level access or higher to access sensitive information from third-party orders. This vulnerability arises from missing validation on a user-controlled key in the 'generate_document_shortcode' function. Exploitation can lead to unauthorized access to customer names, addresses, email addresses, phone numbers, order details, and invoice information. The vulnerability is only exploitable if the plugin's Document link access type setting is set to 'full', allowing the creation of session-free download links for arbitrary orders.
Users are advised to update the PDF Invoices & Packing Slips for WooCommerce plugin to version 5.15.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 11, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PDF Invoices & Packing Slips | <= 5.14.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2026 | New CVE Received | [email protected] |
Volerion