<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:pdf_invoices_packing_slips_for_woocommerce:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpresspdf_invoices_packing_slips_for_woocommerce/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:40:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpresspdf_invoices_packing_slips_for_woocommerce/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in WooCommerce PDF Invoices &amp; Packing Slips Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92244/</link><pubDate>Thu, 01 Oct 2026 10:40:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92244/</guid><description>The PDF Invoices &amp; Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via billing fields, allowing unauthenticated attackers to execute arbitrary scripts in administrative sessions.</description><content:encoded><![CDATA[<p>The PDF Invoices &amp; Packing Slips for WooCommerce plugin for WordPress (versions up to and including 5.16.1) contains a critical security flaw involving Stored Cross-Site Scripting (XSS). The vulnerability exists within the billing information input fields, specifically the 'First Name', 'Last Name', and 'Company' fields. Due to insufficient input sanitization and output escaping, the plugin fails to properly handle malicious inputs. Specifically, the sanitization functions sanitize_text_field() and wc_clean() in WooCommerce are insufficient for preventing the storage of entity-encoded scripts that do not contain the literal '&lt;' character. An unauthenticated attacker can exploit this during the WooCommerce guest checkout process by submitting malicious payloads within these billing fields. When an administrator or authorized user views the corresponding invoice or packing slip, the payload executes in their browser context, potentially leading to unauthorized actions or credential theft.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session, typically an administrator. This can result in session hijacking, unauthorized administrative actions, or the further compromise of the WordPress environment. This vulnerability affects any e-commerce site utilizing the plugin for order management.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update the PDF Invoices &amp; Packing Slips for WooCommerce plugin to the latest version, ensuring it is beyond version 5.16.1.</li>
<li>Implement a strict Content Security Policy (CSP) to mitigate the impact of XSS attacks by restricting the execution of inline scripts and unauthorized external domains.</li>
<li>Regularly audit WooCommerce order logs for anomalous characters or suspicious entity-encoded strings within billing metadata.</li>
<li>Restrict access to administrative areas of the WordPress dashboard to known, secure IP addresses to reduce the exposure of potential victims.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category><category>ecommerce</category></item></channel></rss>