Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.3

PDF Invoices & Packing Slips for WooCommerce plugin allows attackers to modify customer data

CVE-2026-1906
Summary

A security issue in the PDF Invoices & Packing Slips for WooCommerce plugin allows an attacker with a low-level account to change sensitive customer information. This could disrupt payments and lead to data exposure. Update the plugin to the latest version to fix the issue.

Original title
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_c...
Original description
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_customer_peppol_identifiers` AJAX action due to missing capability checks and order ownership validation. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify Peppol/EDI endpoint identifiers (`peppol_endpoint_id`, `peppol_endpoint_eas`) for any customer by specifying an arbitrary `order_id` parameter on systems using Peppol invoicing. This can affect order routing on the Peppol network and may result in payment disruptions and data leakage.
nvd CVSS3.1 4.3
Vulnerability type
CWE-862 Missing Authorization
Published: 18 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026