PLUGIN SECURITY
Is Woocommerce Pdf Invoices Packing Slips safe?
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
What this plugin does
- Slug:
woocommerce-pdf-invoices-packing-slips - Author: WP Overnight
- 300000+ active installs
- 100/100 rating (1862 reviews on wordpress.org)
- 23681625 all-time downloads
- On WordPress.org since 2014-01-17
invoicespacking slipspdfublwoocommerce
Maintenance status
- Latest known version: 5.15.2
- Last updated: 2026-08-21 7:43am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
13 known CVEs on file for Woocommerce Pdf Invoices Packing Slips.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-13116 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0 | Authorization Bypass Through User-Controlled Key | Medium 4.3 | < 5.15.0 | 5.15.0 | 2026-07-10 | ✓ fixed in latest |
| CVE-2026-39472 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.9.0 | Deserialization of Untrusted Data | High 7.2 | < 5.9.0 | 5.9.0 | 2026-04-20 | ✓ fixed in latest |
| CVE-2025-67589 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.0.0 | Missing Authorization | Medium 4.3 | < 5.0.0 | 5.0.0 | 2025-12-07 | ✓ fixed in latest |
| CVE-2024-50421 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.7 | Missing Authorization | Medium 5.3 | < 3.8.7 | 3.8.7 | 2024-10-24 | ✓ fixed in latest |
| CVE-2024-3045 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.8.1 | 3.8.1 | 2024-04-24 | ✓ fixed in latest |
| CVE-2024-3047 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.8.1 | Server-Side Request Forgery (SSRF) | High 7.2 | < 3.8.1 | 3.8.1 | 2024-04-24 | ✓ fixed in latest |
| CVE-2024-22147 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.6 | < 3.7.6 | 3.7.6 | 2024-01-12 | ✓ fixed in latest |
| CVE-2022-47148 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.2.6 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 3.2.6 | 3.2.6 | 2023-01-27 | ✓ fixed in latest |
+ 12 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-2537 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 3.0.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.0.1 | 3.0.1 | 2022-08-03 | ✓ fixed in latest |
| CVE-2022-2092 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.16.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.16.0 | 2.16.0 | 2022-06-16 | ✓ fixed in latest |
| — | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 | — | Unknown | < 2.15.0 | 2.15.0 | 2022-06-07 | ✓ fixed in latest |
| — | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15 | — | Unknown | < 2.15 | 2.15 | 2022-06-07 | ✓ fixed in latest |
| CVE-2021-24991 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.10.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.10.5 | 2.10.5 | 2021-12-06 | ✓ fixed in latest |
| — | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 | — | Unknown | < 2.0.13 | 2.0.13 | 2017-10-05 | ✓ fixed in latest |
| CVE-2017-18506 | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.0.13 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.0.13 | 2.0.13 | 2017-10-02 | ✓ fixed in latest |
| — | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.7.0 | — | Unknown | < 5.7.0 | 5.7.0 | 0000-00-00 | ✓ fixed in latest |
| — | PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 2.15.0 | — | Unknown | < 2.15.0 | 2.15.0 | — | ✓ fixed in latest |
| — | WooCommerce PDF Invoices & Packing Slips < 2.15.0 - Reflected Cross-Site Scripting | — | Unknown | < 2.15.0 | 2.15.0 | — | ✓ fixed in latest |
| CVE-2024-22147 | PDF Invoices & Packing Slips for WooCommerce < 3.7.6 - Shop Manager+ SQL Injection | — | Unknown | < 3.7.6 | 3.7.6 | — | ✓ fixed in latest |
| CVE-2026-1906 | PDF Invoices & Packing Slips for WooCommerce < 5.7.0 - Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification | — | Unknown | < 5.7.0 | 5.7.0 | — | ✓ fixed in latest |
How to fix it
Keep Woocommerce Pdf Invoices Packing Slips updated — 5.15.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels — 50000+ active installs — 98/100 (284) — max PHP 8.4
- Print Invoice & Delivery Notes for WooCommerce — 30000+ active installs — 88/100 (137) — max PHP <8.0
- Invoices for WooCommerce — 10000+ active installs — 94/100 (469) — max PHP 8.4
- PDF Builder for WooCommerce. Create invoices,packing slips and more — 2000+ active installs — 94/100 (145)
- PDF Generator for WordPress — 1000+ active installs — 92/100 (39)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.