plugin

Woocommerce Pdf Invoices Packing Slips Vulnerabilities

29 known security issues reported for the Woocommerce Pdf Invoices Packing Slips WordPress plugin. Most recent disclosed Jul 10, 2026.

3 high 11 medium

Running Woocommerce Pdf Invoices Packing Slips on your site? Check whether your installed version is affected.

Scan your site free

PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute

medium

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributo...

CVSS:
4.3
Affected:
up to 5.14.0
Fixed in:
5.15.0
Disclosed:
Jul 10, 2026

CVE-2026-13116 on NVD →

PDF Invoices & Packing Slips for WooCommerce < 5.9.0 - Authenticated (Shop manager+) PHP Object Injection

medium

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to 5.9.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject a PHP Object. No known POP chain is present...

CVSS:
6.6
Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Apr 20, 2026

CVE-2026-39472 on NVD →

PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 - Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification

medium

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_customer_peppol_identifiers` AJAX action due to missing capability checks and order ownership validation. This makes it poss...

CVSS:
4.3
Affected:
up to 5.6.0
Fixed in:
5.7.0
Disclosed:
Feb 17, 2026

CVE-2026-1906 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] <= 4.9.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 4.9.1.

Affected:
up to 4.9.1
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67589 on NVD →

WooCommerce PDF Invoices & Packing Slips <= 4.9.1 - Missing Authorization

medium

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized...

CVSS:
4.3
Affected:
up to 4.9.1
Fixed in:
5.0.0
Disclosed:
Dec 7, 2025

CVE-2025-67589 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.7 (closed)

unknown

[en] Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through 3.8.6.

Affected:
up to 3.8.7
Fixed in:
3.8.7
Disclosed:
Oct 29, 2024

CVE-2024-50421 on NVD →

WooCommerce PDF Invoices & Packing Slips <= 3.8.6 - Missing Authorization

medium

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.8.6
Fixed in:
3.8.7
Disclosed:
Oct 24, 2024

CVE-2024-50421 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 (closed)

unknown

[en] The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can...

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
May 2, 2024

CVE-2024-3047 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 (closed)

unknown

[en] The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 3.8.1
Fixed in:
3.8.1
Disclosed:
May 2, 2024

CVE-2024-3045 on NVD →

PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting

high

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
7.2
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Apr 24, 2024

CVE-2024-3045 on NVD →

PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery

high

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be us...

CVSS:
7.2
Affected:
up to 3.8.0
Fixed in:
3.8.1
Disclosed:
Apr 24, 2024

CVE-2024-3047 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.7.6 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5.

Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Jan 26, 2024

CVE-2024-22147 on NVD →

PDF Invoices & Packing Slips for WooCommerce <= 3.7.6 - Authenticated (Shop Manager+) SQL Injection

high

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the get_numbers() function in all versions up to, and including, 3.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

CVSS:
7.2
Affected:
up to 3.7.6
Fixed in:
3.7.7
Disclosed:
Jan 12, 2024

CVE-2024-22147 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.7.6 (closed)

unknown

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the get_numbers() function in all versions up to, and including, 3.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

Affected:
up to 3.7.6
Fixed in:
3.7.6
Disclosed:
Jan 12, 2024

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.2.6 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Mar 1, 2023

CVE-2022-47148 on NVD →

WooCommerce PDF Invoices & Packing Slips <= 3.2.5 - Cross Site Request Forgery

medium

The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.5. This is due to missing or incorrect nonce validation on the attachment_settings_hint() function. This makes it possible for unauthenticated attackers to change the hide...

CVSS:
4.3
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Jan 27, 2023

CVE-2022-47148 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.0.1 (closed)

unknown

[en] The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

Affected:
up to 3.0.1
Fixed in:
3.0.1
Disclosed:
Aug 29, 2022

CVE-2022-2537 on NVD →

WooCommerce PDF Invoices & Packing Slips 2.14.0 - 3.0.0 - Reflected Cross-Site Scripting

medium

The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.14.0 up to 3.0.0 via its tabs and section parameters due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

CVSS:
6.1
Affected:
2.14.0 – 3.0.0
Fixed in:
3.0.1
Disclosed:
Aug 3, 2022

CVE-2022-2537 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.16.0 (closed)

unknown

[en] The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.

Affected:
up to 2.16.0
Fixed in:
2.16.0
Disclosed:
Jul 11, 2022

CVE-2022-2092 on NVD →

WooCommerce PDF Invoices & Packing Slips <= 2.15.0 - Reflected Cross-Site Scripting

medium

The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'preview' parameter in versions up to, and including, 2.15.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages...

CVSS:
5.4
Affected:
up to 2.15.0
Fixed in:
2.16.0
Disclosed:
Jun 16, 2022

CVE-2022-2092 on NVD →

WooCommerce PDF Invoices & Packing Slips <= 2.14.5 - Cross-Site Scripting

medium

The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
2.14.5 – 2.14.5
Fixed in:
2.15
Disclosed:
Jun 7, 2022

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 (closed)

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress WooCommerce PDF Invoices & Packing Slips plugin (versions <= 2.14.5). Update the WordPress WooCommerce PDF Invoices & Packing Slips plugin to the latest available (at least 2.15.0).

Affected:
up to 2.15.0
Fixed in:
2.15.0
Disclosed:
Jun 7, 2022

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15 (closed)

unknown

The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

Affected:
up to 2.15
Fixed in:
2.15
Disclosed:
Jun 7, 2022

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.10.5 (closed)

unknown

[en] The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

Affected:
up to 2.10.5
Fixed in:
2.10.5
Disclosed:
Jan 3, 2022

CVE-2021-24991 on NVD →

WooCommerce PDF Invoices & Packing Slips <= 2.10.4 - Reflected Cross-Site Scripting via tab and section parameter

medium

The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

CVSS:
4.8
Affected:
up to 2.10.5
Fixed in:
2.10.5
Disclosed:
Dec 6, 2021

CVE-2021-24991 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 (closed)

unknown

[en] The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Aug 12, 2019

CVE-2017-18506 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 (closed)

unknown

Cross-Site Scripting (XSS) vulnerability found by Detectify in WordPress WooCommerce PDF Invoices & Packing Slips plugin (versions <=2.0.12).

Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Oct 5, 2017

WooCommerce PDF Invoices & Packing Slips <= 2.0.12 - Cross-Site Scripting

medium

The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.

CVSS:
6.1
Affected:
up to 2.0.13
Fixed in:
2.0.13
Disclosed:
Oct 2, 2017

CVE-2017-18506 on NVD →

PDF Invoices &amp; Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 (closed)

unknown

The plugin does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 2.15.0
Fixed in:
2.15.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database