rootpwn

high · CVSS v3 7.2

CVE-2026-92244

The PDF Invoices & Packing Slips plugin for WooCommerce is vulnerable to stored cross‑site scripting via billing fields. Unauthenticated use

Overview

The PDF Invoices & Packing Slips plugin for WooCommerce is vulnerable to stored cross‑site scripting via billing fields. Unauthenticated users can inject scripts that execute when any user views an invoice. This can lead to session hijacking, defacement, or data theft.

Description

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives initial storage because WooCommerce's sanitize_text_field() and wc_clean() do not strip entity-encoded strings containing no literal '<' character, allowing unauthenticated guest-checkout orders to plant the malicious content.

Impact

Confidentiality: attackers can steal session cookies or other sensitive data. Integrity: malicious scripts can alter invoice content or inject malware. Availability: minimal direct impact. Defenders: site administrators, developers, and end users are affected.

Remediation

Update the plugin to version 5.16.2 or later. If an update is not possible, sanitize billing fields on input or disable guest checkout. Implement a Content Security Policy that blocks inline scripts and restricts script sources.

Risk context

High severity (CVSS 7.2) with no EPSS data. Attackers can exploit this flaw without authentication, so prompt patching is recommended.

Affected products

  • WooCommerce PDF Invoices & Packing Slips
  • WordPress

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
—

XSS WooCommerce PDF Stored XSS WordPress Guest Checkout Input Sanitization

← All CVEs