PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute
medium
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributo...
- CVSS:
- 4.3
- Affected:
- up to 5.14.0
- Fixed in:
- 5.15.0
- Disclosed:
- Jul 10, 2026
CVE-2026-13116 on NVD →
PDF Invoices & Packing Slips for WooCommerce < 5.9.0 - Authenticated (Shop manager+) PHP Object Injection
medium
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to 5.9.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with shop manager-level access and above, to inject a PHP Object. No known POP chain is present...
- CVSS:
- 6.6
- Affected:
- up to 5.9.0
- Fixed in:
- 5.9.0
- Disclosed:
- Apr 20, 2026
CVE-2026-39472 on NVD →
PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 - Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification
medium
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_customer_peppol_identifiers` AJAX action due to missing capability checks and order ownership validation. This makes it poss...
- CVSS:
- 4.3
- Affected:
- up to 5.6.0
- Fixed in:
- 5.7.0
- Disclosed:
- Feb 17, 2026
CVE-2026-1906 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] <= 4.9.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 4.9.1.
- Affected:
- up to 4.9.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67589 on NVD →
WooCommerce PDF Invoices & Packing Slips <= 4.9.1 - Missing Authorization
medium
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.9.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 4.9.1
- Fixed in:
- 5.0.0
- Disclosed:
- Dec 7, 2025
CVE-2025-67589 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.7 (closed)
unknown
[en] Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through 3.8.6.
- Affected:
- up to 3.8.7
- Fixed in:
- 3.8.7
- Disclosed:
- Oct 29, 2024
CVE-2024-50421 on NVD →
WooCommerce PDF Invoices & Packing Slips <= 3.8.6 - Missing Authorization
medium
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.8.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.8.6
- Fixed in:
- 3.8.7
- Disclosed:
- Oct 24, 2024
CVE-2024-50421 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 (closed)
unknown
[en] The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can...
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- May 2, 2024
CVE-2024-3047 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 (closed)
unknown
[en] The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- May 2, 2024
CVE-2024-3045 on NVD →
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting
high
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 7.2
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 24, 2024
CVE-2024-3045 on NVD →
PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery
high
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be us...
- CVSS:
- 7.2
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Apr 24, 2024
CVE-2024-3047 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.7.6 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5.
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Jan 26, 2024
CVE-2024-22147 on NVD →
PDF Invoices & Packing Slips for WooCommerce <= 3.7.6 - Authenticated (Shop Manager+) SQL Injection
high
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the get_numbers() function in all versions up to, and including, 3.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...
- CVSS:
- 7.2
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.7
- Disclosed:
- Jan 12, 2024
CVE-2024-22147 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.7.6 (closed)
unknown
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the get_numbers() function in all versions up to, and including, 3.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Jan 12, 2024
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.2.6 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Mar 1, 2023
CVE-2022-47148 on NVD →
WooCommerce PDF Invoices & Packing Slips <= 3.2.5 - Cross Site Request Forgery
medium
The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.5. This is due to missing or incorrect nonce validation on the attachment_settings_hint() function. This makes it possible for unauthenticated attackers to change the hide...
- CVSS:
- 4.3
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Jan 27, 2023
CVE-2022-47148 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.0.1 (closed)
unknown
[en] The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.1
- Disclosed:
- Aug 29, 2022
CVE-2022-2537 on NVD →
WooCommerce PDF Invoices & Packing Slips 2.14.0 - 3.0.0 - Reflected Cross-Site Scripting
medium
The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions 2.14.0 up to 3.0.0 via its tabs and section parameters due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 6.1
- Affected:
- 2.14.0 – 3.0.0
- Fixed in:
- 3.0.1
- Disclosed:
- Aug 3, 2022
CVE-2022-2537 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.16.0 (closed)
unknown
[en] The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.
- Affected:
- up to 2.16.0
- Fixed in:
- 2.16.0
- Disclosed:
- Jul 11, 2022
CVE-2022-2092 on NVD →
WooCommerce PDF Invoices & Packing Slips <= 2.15.0 - Reflected Cross-Site Scripting
medium
The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'preview' parameter in versions up to, and including, 2.15.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages...
- CVSS:
- 5.4
- Affected:
- up to 2.15.0
- Fixed in:
- 2.16.0
- Disclosed:
- Jun 16, 2022
CVE-2022-2092 on NVD →
WooCommerce PDF Invoices & Packing Slips <= 2.14.5 - Cross-Site Scripting
medium
The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- CVSS:
- 6.1
- Affected:
- 2.14.5 – 2.14.5
- Fixed in:
- 2.15
- Disclosed:
- Jun 7, 2022
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 (closed)
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress WooCommerce PDF Invoices & Packing Slips plugin (versions <= 2.14.5).
Update the WordPress WooCommerce PDF Invoices & Packing Slips plugin to the latest available (at least 2.15.0).
- Affected:
- up to 2.15.0
- Fixed in:
- 2.15.0
- Disclosed:
- Jun 7, 2022
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15 (closed)
unknown
The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- Affected:
- up to 2.15
- Fixed in:
- 2.15
- Disclosed:
- Jun 7, 2022
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.10.5 (closed)
unknown
[en] The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
- Affected:
- up to 2.10.5
- Fixed in:
- 2.10.5
- Disclosed:
- Jan 3, 2022
CVE-2021-24991 on NVD →
WooCommerce PDF Invoices & Packing Slips <= 2.10.4 - Reflected Cross-Site Scripting via tab and section parameter
medium
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
- CVSS:
- 4.8
- Affected:
- up to 2.10.5
- Fixed in:
- 2.10.5
- Disclosed:
- Dec 6, 2021
CVE-2021-24991 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 (closed)
unknown
[en] The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.13
- Disclosed:
- Aug 12, 2019
CVE-2017-18506 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 (closed)
unknown
Cross-Site Scripting (XSS) vulnerability found by Detectify in WordPress WooCommerce PDF Invoices & Packing Slips plugin (versions <=2.0.12).
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.13
- Disclosed:
- Oct 5, 2017
WooCommerce PDF Invoices & Packing Slips <= 2.0.12 - Cross-Site Scripting
medium
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
- CVSS:
- 6.1
- Affected:
- up to 2.0.13
- Fixed in:
- 2.0.13
- Disclosed:
- Oct 2, 2017
CVE-2017-18506 on NVD →
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 (closed)
unknown
The plugin does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.15.0
- Fixed in:
- 2.15.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database