EInvoice App Malaysia
EInvoice App Malaysia has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for EInvoice App Malaysia has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Rapid0nion. The current release is tested up to WordPress 6.8.8.
CVE-2025-68988E-Invoice App Malaysia <= 1.3.0 - Unauthenticated Information Exposure
Read the full analysisVulnerability Records

EInvoice App Malaysia
Author
o2oe
woocommerceOur app acts as a middleware between your store and Malaysia’s LHDN e-invoice system. It temporarily collects customer checkout information, allowing customers to fill in any missing details. Once the data is complete, the app submits the information to the LHDN e-invoice system for validation, ensuring compliance with Malaysia’s tax regulations. Collects customer checkout info and lets them fill in missing details easily. Submits completed data to Malaysia’s LHDN e-invoice system for validation. Easily integrates with Woocommerce to streamline the checkout and invoicing process. External Services This plugin connects to the following external APIs to provide e-invoice functionality compliant with Malaysia’s LHDN requirements: 1. E-Invoice App Malaysia API Service Provider: o2o Ecommerce Sdn Bhd Purpose: Generates and submits e-invoices to LHDN. Manages invoice/note records for WooCommerce orders. Data Sent: Order details (total, tax, items, quantities). Customer info (name, email, billing address, tax). Store/merchant registration details (for LHDN compliance). When Data is Sent: When an admin/customer request for e-invoice. When an admin create the consolidated e-invoice. When an admin register for their store. When an admin cancel e-invoice. When an admin create/cancel credit note. When an admin create/cancel debit note. When an admin create/cancel refund note. Endpoint: https://api.einvoiceapp.my Privacy Policy: https://www.webceo.my/einvoice-app-for-woocommerce-privacy-policy 2. Development/Staging API (Optional) Service Provider: o2o Ecommerce Sdn Bhd Purpose: Testing e-invoice generation during development. Data Sent: Same as production API (mock data for testing). Endpoint: https://dev-api.einvoiceapp.my Note: Only active if plugin is in development mode. License & Credits This plugin includes the following third-party libraries: Select 2 source: https://select2.org/ License MIT (https://github.com/select2/select2/blob/develop/LICENSE.md) QRCode.js source: https://davidshimjs.github.io/qrcodejs/ License MIT (https://github.com/davidshimjs/qrcodejs/blob/master/LICENSE) Bootstrap source: https://getbootstrap.com/ License MIT (https://github.com/twbs/bootstrap/blob/main/LICENSE) JQuery UI source: http://jqueryui.com License MIT (https://github.com/jquery/jquery-ui/blob/main/LICENSE.txt)
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C