PDF Builder for WooCommerce. Create invoices,packing slips and more
woo-pdf-invoice-builder · plugin
Known security vulnerabilities for PDF Builder for WooCommerce. Create invoices,packing slips and more. Find out in seconds which version runs on your site with WP Lens.
14 known vulnerabilities
1 critical · 7 exploitable without logging in · latest Sep 19, 2026
Listed on wordpress.org · latest 2.0.17 · last updated Sep 25, 2026 · 2K+ installs
wordpress.org status checked on Oct 5, 2026
Vulnerabilities
- Critical 10.0
CVE-2026-52704unauthenticated≤ 2.0.8
WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Remote Code Execution (RCE) vulnerability
- High 8.8
CVE-2023-51486unauthenticated · needs a click≤ 1.2.101
WordPress WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <= 1.2.101 - Cross Site Request Forgery (CSRF) vulnerability
- High 8.8
CVE-2023-3677subscriber+≤ 1.2.89
WooCommerce PDF Invoice Builder <= 1.2.89 - Authenticated (Subscriber+) SQL Injection via Export
- Medium 6.5
CVE-2026-11496subscriber+≤ 2.0.8
Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure
- Medium 6.5
CVE-2026-57393login required≤ 2.0.8
WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability
- Medium 6.1
CVE-2024-11276unauthenticated · needs a click≤ 1.2.136
PDF Builder for WooCommerce. Create invoices,packing slips and more <= 1.2.136 - Reflected Cross-Site Scripting
- Medium 6.1
CVE-2023-46076unauthenticated · needs a click≤ 1.2.102
WordPress WooCommerce PDF Invoice Builder Plugin <= 1.2.102 is vulnerable to Cross Site Scripting (XSS)
- Medium 4.8
CVE-2023-4160admin≤ 1.2.90
WooCommerce PDF Invoice Builder <= 1.2.90 - Authenticated (Administrator+) Cross-Site Scripting
- Medium 4.3
CVE-2025-53203unauthenticated · needs a click≤ 1.2.148
WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.148 - Cross Site Request Forgery (CSRF) Vulnerability
- Medium 4.3
CVE-2023-4161unauthenticated · needs a click≤ 1.2.90
WooCommerce PDF Invoice Builder <= 1.2.90 - Cross-Site Request Forgery to Custom Field Creation
- Medium 4.3
CVE-2023-3764unauthenticated · needs a click≤ 1.2.90
WooCommerce PDF Invoice Builder <= 1.2.90 - Cross-Site Request Forgery via Save
- Medium 4.3
CVE-2026-11899subscriber+≤ 2.0.11
PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disc
- Medium 4.3
CVE-2025-64269login required≤ 1.2.150
WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability
- Medium 4.3
CVE-2023-4245login required≤ 1.2.91
WooCommerce PDF Invoice Builder <= 1.2.89 - Missing Authorization to Sensitive Information Exposure
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).