A new vulnerability in WebToffee WooCommerce could allow low-privileged users to read arbitrary files from an online store's server. CVE-2026-18027 concerns the invoice and packing slip generation plugin and requires immediate attention from WordPress administrators.

The vulnerability was reported as a path traversal and allows reading of content that should not normally be available through the print or invoice download functions. The SecNews technical team evaluated the researcher's listing and available data to separate the real risk from exaggerated descriptions.
The affected plugin is used in WooCommerce stores to generate PDF invoices, shipping notes, and other order documents. The presence of WebToffee WooCommerce does not automatically mean that a website has been compromised, but it does raise the need for version control and accounts with access to WordPress.
See also: New security flaw in WordPress B2BKing
How the WebToffee WooCommerce vulnerability works
According to Wordfence's analysis, the issue lies in the get_image_src_in_base64 and is linked to the customer_note. The parameter value can be used to request a file outside the intended directory when following the document creation or viewing flow.
The contents of the file are converted to base64 format and embedded in the cached HTML of the invoice. This may expose application settings, log files, or other data located on the same server. The exact extent depends on the permissions of the website account and the files that are readable by the PHP code.

CVE -2026-18027 is not an anonymous attack from the Internet. Exploitation requires an account with the Subscriber level or higher, a valid nonce, and an access key used by access points for printing and downloading. However, a low-level account that has been stolen or created through social engineering can be a starting point for leaking sensitive files.
Which versions of WebToffee WooCommerce are affected?
The listing affects all versions of WebToffee WooCommerce up to 4.9.8. The plugin page on WordPress.org now shows version 5.0.1, which was released on August 20, 2026. Administrators should not assume an installation is safe just because the plugin is working properly or because no suspicious orders have been seen.
Wordfence scores CVE-2026-18027 6.5/10 with CVSS 3.1, due to the low privileges and specific access flow required. The confidentiality impact remains high: a configuration file or backup could contain credentials, service keys, and personal customer data.
For this reason, the security team should look not only at the add-on version but also at active accounts, recent user changes, and billing access point logs. The absence of any log entries does not rule out a file being read, especially if the logs are deleted quickly or do not record the entire request.
See also: Vulnerabilities in WordPress plugin threaten websites

What should administrators do?
The first step is to upgrade WebToffee WooCommerce to the latest available version from the official repository or from the WordPress admin panel. Before making the change, a recent backup is required and, for online stores with high traffic, testing in a separate environment is required to ensure that invoices and shipments are not disrupted.
In addition, delete unnecessary accounts, enforce unique passwords, and enable multi-factor login where supported. Also, check if the plugin has created temporary HTML files with invoice content and restrict access to them at the server level.
If there are signs of suspicious usage, keep a copy of the logs before any cleanup, change any credentials that may have existed in configuration files, and check orders for unexpected changes. Upgrading reduces the risk, but does not undo data that may have already been copied.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: WPeMatico RSS: Critical vulnerability in WordPress plugin

CVE-2026-18027 shows that even an account with limited privileges can become vulnerable when a plugin manipulates files without sufficient path checking. WebToffee WooCommerce users should immediately confirm their version, install the update, and check for signs of accessing documents or files outside of the normal operation of the store.
