WordPress WooCommerce PDF Invoice Builder Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in the WordPress WooCommerce PDF Invoice Builder plugin, specifically in versions through 2.0.8. This issue allows for the retrieval of embedded sensitive data that is not typically accessible to regular users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, which could be used to exploit other weaknesses in the system.

Remediation

Users of the WooCommerce PDF Invoice Builder plugin should update to version 2.0.9 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jul 13, 2026, 11:18 AM
Updated: Jul 13, 2026, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.