Answer in brief
CVE-2026-93746 records a High severity (CVSS 7.5) vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 5.0.2 - Insecure Direct Object Reference to Unauthenticated Unauthorized Order Document Access via 'email' Parameter. The current sources do not mark it as known exploited. The current feed maps webtoffee/WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps webtoffee/WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| webtoffee/WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labelsgeneric | >=0 <=5.0.2 | Not reported |
Published upstream
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 10, 2026
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_document_from_the_mail_link handler dispatched from print_window() on init. This is due to the handler authorizing access to an order's printable documents when the attacker-supplied (base64-encoded) 'email' equals the order's billing email — a non-secret identifier — instead of requiring the WooCommerce order_key. This makes it possible for unauthenticated attackers, when the site is configured to allow guest access to documents ('wt_pklist_print_button_access_for' != 'logged_in'), to retrieve any other customer's invoice, packing slip, delivery note, dispatch label or shipping label — including customer name, billing/shipping address, phone number, purchased products, prices, taxes and invoice metadata — by knowing the target order ID and the associated billing email address.
Quoted source text, attributed separately from HOL analysis.