CVE-2026-1906
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1906 is an Insecure Direct Object Reference (IDOR) vulnerability in the PDF Invoices & Packing Slips for WooCommerce WordPress plugin, affecting all versions up to and including 5.6.0. The flaw exists in the wpo_ips_edi_save_order_customer_peppol_identifiers AJAX action, which lacks both capability checks and order ownership validation. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the AJAX action wpo_ips_edi_save_order_customer_peppol_identifiers does not verify that the requesting user has sufficient privileges or that they own the order being modified. An authenticated attacker with Subscriber-level access (or higher) can supply an arbitrary order_id parameter in a crafted AJAX request to overwrite the Peppol/EDI endpoint identifiers (peppol_endpoint_id, peppol_endpoint_eas) of any customer's order. No special configuration beyond having a WordPress account is required; the attack is network-accessible and requires no user interaction (Feedly, Beazley Advisory).

Impact

Successful exploitation allows an authenticated low-privileged attacker to tamper with Peppol/EDI routing identifiers on any order in the WooCommerce store. This can misdirect electronic invoices on the Peppol network, potentially causing payment disruptions, invoice fraud, and leakage of order-related business data to unintended recipients. The confidentiality impact is limited (no direct data read), but integrity is compromised through unauthorized modification of financial routing data (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.026%, indicating a low probability of near-term exploitation. Exploitation requires only a valid WordPress subscriber account, lowering the barrier for authenticated attackers on multi-user sites (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a WordPress site running the PDF Invoices & Packing Slips for WooCommerce plugin version ≤ 5.6.0 with Peppol/EDI invoicing enabled.
  2. Obtain low-privilege account: Register or obtain a Subscriber-level (or higher) WordPress account on the target site.
  3. Enumerate order IDs: Use the WooCommerce storefront or other accessible endpoints to identify valid order_id values belonging to other customers (e.g., by observing order confirmation URLs or brute-forcing sequential IDs).
  4. Craft malicious AJAX request: Send an authenticated POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action wpo_ips_edi_save_order_customer_peppol_identifiers, specifying the target order_id and attacker-controlled peppol_endpoint_id and peppol_endpoint_eas values.
  5. Achieve impact: The plugin updates the Peppol routing identifiers for the targeted order without authorization checks, redirecting future electronic invoices to the attacker-controlled endpoint on the Peppol network (Feedly, Beazley Advisory).

Indicators of compromise

  • Logs: WordPress access logs showing repeated POST requests to /wp-admin/admin-ajax.php with action=wpo_ips_edi_save_order_customer_peppol_identifiers and varying order_id values from a single authenticated session.
  • Logs: WooCommerce or plugin logs recording unexpected changes to peppol_endpoint_id or peppol_endpoint_eas fields across multiple orders not owned by the modifying user.
  • Database: Unexpected or unfamiliar Peppol endpoint identifiers in the WooCommerce order meta table (wp_postmeta) for fields peppol_endpoint_id and peppol_endpoint_eas.
  • Network: Peppol network delivery failures or bounce notifications for invoices routed to unknown or external endpoint identifiers.

Mitigation and workarounds

Users should update the PDF Invoices & Packing Slips for WooCommerce plugin to a version above 5.6.0 that includes proper capability checks and order ownership validation in the affected AJAX action. Until a patch is applied, site administrators can restrict AJAX access to trusted roles only via a WAF rule, or temporarily disable Peppol/EDI functionality if not business-critical. Monitor WooCommerce order meta for unexpected changes to Peppol endpoint fields as a compensating control (Feedly, Sucuri Roundup).

Community reactions

Sucuri included this vulnerability in their February 2026 WordPress vulnerability patch roundup, noting it as a medium-severity IDOR issue affecting WooCommerce Peppol invoicing workflows (Sucuri Roundup). Beazley Security Labs published an independent advisory (BSL-A1158) corroborating the technical details (Beazley Advisory). No significant social media discussion or major media coverage has been identified beyond standard vulnerability database aggregation.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management