Stored Cross-Site Scripting in PDF Invoices & Packing Slips for WooCommerce Plugin
CVE-2026-92244
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-92244?
The PDF Invoices & Packing Slips for WooCommerce plugin is susceptible to Stored Cross-Site Scripting due to inadequate sanitization of input fields, including Billing First Name, Last Name, and Company. This vulnerability allows unauthenticated attackers to inject malicious scripts into these fields, leading to potential exploitation when a user accesses the affected pages. The underlying issue arises from the inadequacy of functions like sanitize_text_field() and wc_clean(), which fail to eliminate certain entity-encoded strings. This oversight permits harmful content to persist through various interactions, putting users at risk during the guest checkout process.
Affected Version(s)
PDF Invoices & Packing Slips for WooCommerce 0 <= 5.16.1