PT-2026-47141 · Unknown · Klamra Paycal For Aspaclaria

·

CVE-2026-8611

·

Published

2026-06-06

·

Updated

2026-06-06

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Klamra Paycal for Aspaclaria versions prior to 1.1.5
Description The plugin is subject to Insecure Direct Object Reference, a condition where an application provides direct access to objects based on user-supplied input. Authenticated attackers with subscriber-level access or higher can download arbitrary customer invoices by enumerating sequential post IDs through the invoice id parameter. This occurs due to missing validation on a user-controlled key, leading to the exposure of sensitive billing personally identifiable information (PII), such as full names, email addresses, phone numbers, order totals, line items, and customer notes.
Recommendations Update the plugin to a version later than 1.1.4. As a temporary workaround, restrict access to the invoice id parameter to prevent unauthorized invoice downloads.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8611

Affected Products

Klamra Paycal For Aspaclaria