Code Injection Vulnerability in WooCommerce PDF Invoice Builder by Edgar Rojas
CVE-2026-52704
10CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-52704?
The WooCommerce PDF Invoice Builder, developed by Edgar Rojas, contains a vulnerability that allows for improper control over the generation of code, leading to remote code inclusion. This flaw poses a significant risk to users by potentially enabling attackers to execute malicious code remotely. It affects versions from n/a to 2.0.8, highlighting the importance of timely updates and security measures for WordPress environments utilizing this plugin.
Affected Version(s)
WooCommerce PDF Invoice Builder <= 2.0.8