PT-2026-49237 · WordPress · Woocommerce Pdf Invoice Builder

·

CVE-2026-52704

·

Published

2026-06-15

·

Updated

2026-06-16

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce PDF Invoice Builder versions prior to 2.0.9
Description Improper Control of Generation of Code allows Remote Code Inclusion, enabling an unauthenticated attacker to perform full code injection via remote file inclusion.
Recommendations Update to a version newer than 2.0.8.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52704

Affected Products

Woocommerce Pdf Invoice Builder