Impact
The WooCommerce PDF Invoices & Packing Slips plugin is vulnerable to stored cross‑site scripting via the billing first name, last name and company fields. The vulnerability exists because the plugin fails to properly sanitize or escape input; entity‑encoded strings that do not contain a literal '<' character survive. As a result, unauthenticated attackers can inject arbitrary JavaScript payloads that execute in the context of any browser that views a page containing the injected content.
Affected Systems
This weakness affects all releases of the PDF Invoices & Packing Slips plugin up to and including version 5.16.1, a widely used WordPress plugin for WooCommerce. Users running any of these versions should consider their installations at risk; the affected code paths exist in the plugin’s admin and frontend scripts and settings.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Exploitation can be performed by an unauthenticated attacker simply by creating a guest checkout order that includes malicious content in the billing fields; no additional authentication or privileged access is required. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Because the payload is persisted and later delivered to users, the impact includes defacement, credential theft, or further site compromise.
OpenCVE Enrichment