PLUGIN SECURITY

Is Woocommerce Pdf Invoices Packing Slips safe?

Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.

What this plugin does

  • Slug: woocommerce-pdf-invoices-packing-slips
  • Author: WP Overnight
  • 300000+ active installs
  • 100/100 rating (1862 reviews on wordpress.org)
  • 23681625 all-time downloads
  • On WordPress.org since 2014-01-17

invoicespacking slipspdfublwoocommerce

Maintenance status

  • Latest known version: 5.15.2
  • Last updated: 2026-08-21 7:43am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

13 known CVEs on file for Woocommerce Pdf Invoices Packing Slips.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13116 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0 Authorization Bypass Through User-Controlled Key Medium 4.3 < 5.15.0 5.15.0 2026-07-10 ✓ fixed in latest
CVE-2026-39472 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.9.0 Deserialization of Untrusted Data High 7.2 < 5.9.0 5.9.0 2026-04-20 ✓ fixed in latest
CVE-2025-67589 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.0.0 Missing Authorization Medium 4.3 < 5.0.0 5.0.0 2025-12-07 ✓ fixed in latest
CVE-2024-50421 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.7 Missing Authorization Medium 5.3 < 3.8.7 3.8.7 2024-10-24 ✓ fixed in latest
CVE-2024-3045 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.8.1 3.8.1 2024-04-24 ✓ fixed in latest
CVE-2024-3047 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 Server-Side Request Forgery (SSRF) High 7.2 < 3.8.1 3.8.1 2024-04-24 ✓ fixed in latest
CVE-2024-22147 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 3.7.6 3.7.6 2024-01-12 ✓ fixed in latest
CVE-2022-47148 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.2.6 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.2.6 3.2.6 2023-01-27 ✓ fixed in latest
+ 12 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2537 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.0.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.0.1 3.0.1 2022-08-03 ✓ fixed in latest
CVE-2022-2092 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.16.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.16.0 2.16.0 2022-06-16 ✓ fixed in latest
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 Unknown < 2.15.0 2.15.0 2022-06-07 ✓ fixed in latest
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15 Unknown < 2.15 2.15 2022-06-07 ✓ fixed in latest
CVE-2021-24991 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.10.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.10.5 2.10.5 2021-12-06 ✓ fixed in latest
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 Unknown < 2.0.13 2.0.13 2017-10-05 ✓ fixed in latest
CVE-2017-18506 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.0.13 2.0.13 2017-10-02 ✓ fixed in latest
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.7.0 Unknown < 5.7.0 5.7.0 0000-00-00 ✓ fixed in latest
PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 Unknown < 2.15.0 2.15.0 ✓ fixed in latest
WooCommerce PDF Invoices & Packing Slips < 2.15.0 - Reflected Cross-Site Scripting Unknown < 2.15.0 2.15.0 ✓ fixed in latest
CVE-2024-22147 PDF Invoices & Packing Slips for WooCommerce < 3.7.6 - Shop Manager+ SQL Injection Unknown < 3.7.6 3.7.6 ✓ fixed in latest
CVE-2026-1906 PDF Invoices & Packing Slips for WooCommerce < 5.7.0 - Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification Unknown < 5.7.0 5.7.0 ✓ fixed in latest

How to fix it

Keep Woocommerce Pdf Invoices Packing Slips updated — 5.15.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.