CVE · High

CVE-2026-39472 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.9.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-39472 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.9.0 Deserialization of Untrusted Data High 7.2 < 5.9.0 5.9.0 2026-04-20

CVE-2026-39472

A security flaw exists in WordPress plugins up to version 5.9.0 of PDF Invoices & Packing Slips for WooCommerce due to inadequate handling of unverified input data. This weakness allows authorized users with elevated access levels to introduce a malicious PHP object into the system's environment, potentially leading to unauthorized actions such as deleting files or accessing sensitive information if other vulnerabilities are present on the affected site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.