CVE-2026-18027 | WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels Plugin get_image_src_in_base64 path traversal
A vulnerability classified as problematic was found in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels Plugin up to 4.9.8 on WordPress. Impacted is the function get_image_src_in_base64. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-18027. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More