Vulnerabilities
CVE-2026-1748 - Invoct – PDF Invoices & Billing for WooCommerce <= 1.6 - missing authorization to...
CVE ID : CVE-2026-1748 Published : Feb. 11, 2026, 8:26 a.m. | 49 minutes ago Description : The Invoct – PDF Invoices & Billing for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve invoice clients, invoice items, and list of WordPress users along with their emails. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...