VYPR

Woocommerce Pdf Invoices\& Packing Slips

by Wpovernight

CVEs (9)

  • CVE-2024-22147HigJan 27, 2024
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5.

  • CVE-2024-3047HigMay 2, 2024
    risk 0.40cvss 7.2epss 0.00

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations…

  • CVE-2024-3045HigMay 2, 2024
    risk 0.40cvss 7.2epss 0.01

    The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2022-2537MedAug 29, 2022
    risk 0.40cvss 6.1epss 0.01

    The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.

  • CVE-2022-2092MedJul 11, 2022
    risk 0.40cvss 6.1epss 0.01

    The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.

  • CVE-2017-18506MedAug 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.

  • CVE-2021-24991MedJan 3, 2022
    risk 0.31cvss 4.8epss 0.01

    The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard

  • CVE-2022-47148MedMar 1, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.

  • CVE-2025-24373MedFeb 4, 2025
    risk 0.00cvss 6.5epss 0.00

    woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized users to access any PDF document from a store if they: 1. Have access to a…