Description
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives initial storage because WooCommerce's sanitize_text_field() and wc_clean() do not strip entity-encoded strings containing no literal '<' character, allowing unauthenticated guest-checkout orders to plant the malicious content.
Published: 2026-10-01
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The WooCommerce PDF Invoices & Packing Slips plugin is vulnerable to stored cross‑site scripting via the billing first name, last name and company fields. The vulnerability exists because the plugin fails to properly sanitize or escape input; entity‑encoded strings that do not contain a literal '<' character survive. As a result, unauthenticated attackers can inject arbitrary JavaScript payloads that execute in the context of any browser that views a page containing the injected content.

Affected Systems

This weakness affects all releases of the PDF Invoices & Packing Slips plugin up to and including version 5.16.1, a widely used WordPress plugin for WooCommerce. Users running any of these versions should consider their installations at risk; the affected code paths exist in the plugin’s admin and frontend scripts and settings.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. Exploitation can be performed by an unauthenticated attacker simply by creating a guest checkout order that includes malicious content in the billing fields; no additional authentication or privileged access is required. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Because the payload is persisted and later delivered to users, the impact includes defacement, credential theft, or further site compromise.

Generated by OpenCVE AI on October 1, 2026 at 11:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the PDF Invoices & Packing Slips plugin to version 5.16.2 or newer, which eliminates the input sanitization flaw.
  • Ensure that WordPress and WooCommerce core are updated to the latest stable releases to avoid related issues.
  • Configure a web application firewall or apply a custom filter to sanitize all billing input fields, ensuring that any remaining entity‑encoded strings are properly escaped before rendering.

Generated by OpenCVE AI on October 1, 2026 at 11:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions pdf Invoices & Packing Slips For Woocommerce
Wpovernight
Wpovernight pdf Invoices & Packing Slips For Woocommerce
Vendors & Products Wordpress-extensions
Wordpress-extensions pdf Invoices & Packing Slips For Woocommerce
Wpovernight
Wpovernight pdf Invoices & Packing Slips For Woocommerce

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives initial storage because WooCommerce's sanitize_text_field() and wc_clean() do not strip entity-encoded strings containing no literal '<' character, allowing unauthenticated guest-checkout orders to plant the malicious content.
Title PDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress-extensions Pdf Invoices & Packing Slips For Woocommerce
Wpovernight Pdf Invoices & Packing Slips For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T14:10:55.917Z

Reserved: 2026-09-15T20:18:42.426Z

Link: CVE-2026-92244

cve-icon Vulnrichment

Updated: 2026-10-01T14:10:53.291Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:10.087

Modified: 2026-10-01T15:17:35.560

Link: CVE-2026-92244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')