WordPress security by component
WooCommerce PDF Invoice Builder
Plugin description
WooCommerce PDF Invoice Builder is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 10.
Plugin slug:
woo-pdf-invoice-builderLatest vulnerability
CVE-2026-57393: WooCommerce PDF Invoice Builder: A security weakness
WooCommerce PDF Invoice Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.0.8.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-57393
WooCommerce PDF Invoice Builder: A security weakness
WooCommerce PDF Invoice Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.0.8.
|
2.0.9 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-52704
WooCommerce PDF Invoice Builder: Code execution
WooCommerce PDF Invoice Builder is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.0.8.
|
2.0.9 |
CVE10.0
NVDPending
|
| Nov 13, 2025 |
CVE-2025-64269
WooCommerce PDF Invoice Builder: A security weakness
WooCommerce PDF Invoice Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 27, 2025 |
CVE-2025-53203
WooCommerce PDF Invoice Builder: Cross-site request forgery
WooCommerce PDF Invoice Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 16, 2024 |
CVE-2023-51486
WooCommerce PDF Invoice Builder: Cross-site request forgery
WooCommerce PDF Invoice Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Oct 26, 2023 |
CVE-2023-46076
Woo Pdf Invoice Builder: Cross-site scripting
Woo Pdf Invoice Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Aug 31, 2023 |
CVE-2023-4245
Woo Pdf Invoice Builder: A security weakness
Woo Pdf Invoice Builder is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 31, 2023 |
CVE-2023-4161
Woo Pdf Invoice Builder: Cross-site request forgery
Woo Pdf Invoice Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 31, 2023 |
CVE-2023-4160
WooCommerce PDF Invoice Builder: Cross-site scripting
WooCommerce PDF Invoice Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.8
|
| Aug 31, 2023 |
CVE-2023-3764
WooCommerce PDF Invoice Builder: Cross-site request forgery
WooCommerce PDF Invoice Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 31, 2023 |
CVE-2023-3677
WooCommerce PDF Invoice Builder: SQL injection
WooCommerce PDF Invoice Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|