PT-2026-103742 · WordPress · Woocommerce Pdf Invoices & Packing Slips
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PDF Invoices & Packing Slips for WooCommerce versions prior to 5.16.2
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts through the billing first name, last name, and company fields. The malicious content is preserved because the
sanitize text field() and wc clean() functions do not strip entity-encoded strings that lack a literal '<' character, allowing guest-checkout orders to plant the scripts. These scripts execute whenever a user accesses the affected page.Recommendations
Update to version 5.16.2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Pdf Invoices & Packing Slips