Skip to content
Noroxi

PDF Builder for WooCommerce. Create invoices,packing slips and more

woo-pdf-invoice-builder · plugin

Known security vulnerabilities for PDF Builder for WooCommerce. Create invoices,packing slips and more. Find out in seconds which version runs on your site with WP Lens.

14 known vulnerabilities

1 critical · 7 exploitable without logging in · latest Sep 19, 2026

Listed on wordpress.org · latest 2.0.17 · last updated Sep 25, 2026 · 2K+ installs

wordpress.org status checked on Oct 5, 2026

Vulnerabilities

  • CVE-2026-52704unauthenticated≤ 2.0.8

    WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execution (RCE) vulnerability

    Critical 10.0
  • CVE-2023-51486unauthenticated · needs a click≤ 1.2.101

    WordPress WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <= 1.2.101 - Cross Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2023-3677subscriber+≤ 1.2.89

    WooCommerce PDF Invoice Builder <= 1.2.89 - Authenticated (Subscriber+) SQL Injection via Export

    High 8.8
  • CVE-2026-11496subscriber+≤ 2.0.8

    Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure

    Medium 6.5
  • CVE-2026-57393login required≤ 2.0.8

    WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability

    Medium 6.5
  • CVE-2024-11276unauthenticated · needs a click≤ 1.2.136

    PDF Builder for WooCommerce. Create invoices,packing slips and more <= 1.2.136 - Reflected Cross-Site Scripting

    Medium 6.1
  • CVE-2023-46076unauthenticated · needs a click≤ 1.2.102

    WordPress WooCommerce PDF Invoice Builder Plugin <= 1.2.102 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2023-4160admin≤ 1.2.90

    WooCommerce PDF Invoice Builder <= 1.2.90 - Authenticated (Administrator+) Cross-Site Scripting

    Medium 4.8
  • CVE-2025-53203unauthenticated · needs a click≤ 1.2.148

    WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.148 - Cross Site Request Forgery (CSRF) Vulnerability

    Medium 4.3
  • CVE-2023-4161unauthenticated · needs a click≤ 1.2.90

    WooCommerce PDF Invoice Builder <= 1.2.90 - Cross-Site Request Forgery to Custom Field Creation

    Medium 4.3
  • CVE-2023-3764unauthenticated · needs a click≤ 1.2.90

    WooCommerce PDF Invoice Builder <= 1.2.90 - Cross-Site Request Forgery via Save

    Medium 4.3
  • CVE-2026-11899subscriber+≤ 2.0.11

    PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disc

    Medium 4.3
  • CVE-2025-64269login required≤ 1.2.150

    WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability

    Medium 4.3
  • CVE-2023-4245login required≤ 1.2.91

    WooCommerce PDF Invoice Builder <= 1.2.89 - Missing Authorization to Sensitive Information Exposure

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory