{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pdf-invoices--packing-slips-for-woocommerce--5.16.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:pdf_invoices_packing_slips_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-92244"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PDF Invoices \u0026 Packing Slips for WooCommerce (\u003c= 5.16.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress","ecommerce"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe PDF Invoices \u0026amp; Packing Slips for WooCommerce plugin for WordPress (versions up to and including 5.16.1) contains a critical security flaw involving Stored Cross-Site Scripting (XSS). The vulnerability exists within the billing information input fields, specifically the 'First Name', 'Last Name', and 'Company' fields. Due to insufficient input sanitization and output escaping, the plugin fails to properly handle malicious inputs. Specifically, the sanitization functions sanitize_text_field() and wc_clean() in WooCommerce are insufficient for preventing the storage of entity-encoded scripts that do not contain the literal '\u0026lt;' character. An unauthenticated attacker can exploit this during the WooCommerce guest checkout process by submitting malicious payloads within these billing fields. When an administrator or authorized user views the corresponding invoice or packing slip, the payload executes in their browser context, potentially leading to unauthorized actions or credential theft.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript within the context of a victim's session, typically an administrator. This can result in session hijacking, unauthorized administrative actions, or the further compromise of the WordPress environment. This vulnerability affects any e-commerce site utilizing the plugin for order management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the PDF Invoices \u0026amp; Packing Slips for WooCommerce plugin to the latest version, ensuring it is beyond version 5.16.1.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content Security Policy (CSP) to mitigate the impact of XSS attacks by restricting the execution of inline scripts and unauthorized external domains.\u003c/li\u003e\n\u003cli\u003eRegularly audit WooCommerce order logs for anomalous characters or suspicious entity-encoded strings within billing metadata.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative areas of the WordPress dashboard to known, secure IP addresses to reduce the exposure of potential victims.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T10:40:06Z","date_published":"2026-10-01T10:40:06Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92244/","summary":"The PDF Invoices \u0026 Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via billing fields, allowing unauthenticated attackers to execute arbitrary scripts in administrative sessions.","title":"Stored XSS Vulnerability in WooCommerce PDF Invoices \u0026 Packing Slips Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-92244/"}],"language":"en","title":"CraftedSignal Threat Feed - PDF Invoices \u0026 Packing Slips for WooCommerce (\u003c= 5.16.1)","version":"https://jsonfeed.org/version/1.1"}