Skip to content
Threat Feed
high advisory

Stored XSS Vulnerability in WooCommerce PDF Invoices & Packing Slips Plugin

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via billing fields, allowing unauthenticated attackers to execute arbitrary scripts in administrative sessions.

CVE search metadata

CVE search record: CVE-2026-92244. Severity: high. CVSS: 7.2. KEV: no. Product: PDF Invoices & Packing Slips for WooCommerce (<= 5.16.1). Brief: Stored XSS Vulnerability in WooCommerce PDF Invoices & Packing Slips Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92244/

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress (versions up to and including 5.16.1) contains a critical security flaw involving Stored Cross-Site Scripting (XSS). The vulnerability exists within the billing information input fields, specifically the 'First Name', 'Last Name', and 'Company' fields. Due to insufficient input sanitization and output escaping, the plugin fails to properly handle malicious inputs. Specifically, the sanitization functions sanitize_text_field() and wc_clean() in WooCommerce are insufficient for preventing the storage of entity-encoded scripts that do not contain the literal '<' character. An unauthenticated attacker can exploit this during the WooCommerce guest checkout process by submitting malicious payloads within these billing fields. When an administrator or authorized user views the corresponding invoice or packing slip, the payload executes in their browser context, potentially leading to unauthorized actions or credential theft.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session, typically an administrator. This can result in session hijacking, unauthorized administrative actions, or the further compromise of the WordPress environment. This vulnerability affects any e-commerce site utilizing the plugin for order management.

Recommendation

  1. Update the PDF Invoices & Packing Slips for WooCommerce plugin to the latest version, ensuring it is beyond version 5.16.1.
  2. Implement a strict Content Security Policy (CSP) to mitigate the impact of XSS attacks by restricting the execution of inline scripts and unauthorized external domains.
  3. Regularly audit WooCommerce order logs for anomalous characters or suspicious entity-encoded strings within billing metadata.
  4. Restrict access to administrative areas of the WordPress dashboard to known, secure IP addresses to reduce the exposure of potential victims.

Immediate actions

Upgrade PDF Invoices & Packing Slips for WooCommerce to a version > 5.16.1

IT Operations 24h

Mitigations

Apply Content Security Policy (CSP) headers to restrict script execution

immediate IT Operations

CVE-2026-92244