
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1906 is an Insecure Direct Object Reference (IDOR) vulnerability in the PDF Invoices & Packing Slips for WooCommerce WordPress plugin, affecting all versions up to and including 5.6.0. The flaw exists in the wpo_ips_edi_save_order_customer_peppol_identifiers AJAX action, which lacks both capability checks and order ownership validation. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).
The root cause is classified as CWE-862 (Missing Authorization) — the AJAX action wpo_ips_edi_save_order_customer_peppol_identifiers does not verify that the requesting user has sufficient privileges or that they own the order being modified. An authenticated attacker with Subscriber-level access (or higher) can supply an arbitrary order_id parameter in a crafted AJAX request to overwrite the Peppol/EDI endpoint identifiers (peppol_endpoint_id, peppol_endpoint_eas) of any customer's order. No special configuration beyond having a WordPress account is required; the attack is network-accessible and requires no user interaction (Feedly, Beazley Advisory).
Successful exploitation allows an authenticated low-privileged attacker to tamper with Peppol/EDI routing identifiers on any order in the WooCommerce store. This can misdirect electronic invoices on the Peppol network, potentially causing payment disruptions, invoice fraud, and leakage of order-related business data to unintended recipients. The confidentiality impact is limited (no direct data read), but integrity is compromised through unauthorized modification of financial routing data (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, indicating a low probability of near-term exploitation. Exploitation requires only a valid WordPress subscriber account, lowering the barrier for authenticated attackers on multi-user sites (Feedly).
order_id values belonging to other customers (e.g., by observing order confirmation URLs or brute-forcing sequential IDs)./wp-admin/admin-ajax.php) with the action wpo_ips_edi_save_order_customer_peppol_identifiers, specifying the target order_id and attacker-controlled peppol_endpoint_id and peppol_endpoint_eas values./wp-admin/admin-ajax.php with action=wpo_ips_edi_save_order_customer_peppol_identifiers and varying order_id values from a single authenticated session.peppol_endpoint_id or peppol_endpoint_eas fields across multiple orders not owned by the modifying user.wp_postmeta) for fields peppol_endpoint_id and peppol_endpoint_eas.Users should update the PDF Invoices & Packing Slips for WooCommerce plugin to a version above 5.6.0 that includes proper capability checks and order ownership validation in the affected AJAX action. Until a patch is applied, site administrators can restrict AJAX access to trusted roles only via a WAF rule, or temporarily disable Peppol/EDI functionality if not business-critical. Monitor WooCommerce order meta for unexpected changes to Peppol endpoint fields as a compensating control (Feedly, Sucuri Roundup).
Sucuri included this vulnerability in their February 2026 WordPress vulnerability patch roundup, noting it as a medium-severity IDOR issue affecting WooCommerce Peppol invoicing workflows (Sucuri Roundup). Beazley Security Labs published an independent advisory (BSL-A1158) corroborating the technical details (Beazley Advisory). No significant social media discussion or major media coverage has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."