Junglewise Threat Intelligence

CVE-2026-39472: WooCommerce PDF Invoices & Packing Slips PHP Object Injection

CVE-2026-39472 · Severity: high · CVSS 7.2 · Published 2026-06-15

Executive brief

A security vulnerability exists in the WooCommerce PDF Invoices & Packing Slips plugin, which is used by online stores to generate billing documents. An attacker with shop manager privileges could exploit this flaw to execute unauthorized commands or access sensitive data. This could lead to a full takeover of the website or significant disruption of business operations.

Technical details

The WooCommerce PDF Invoices & Packing Slips plugin for WordPress is vulnerable to PHP Object Injection in versions prior to 5.9.0 due to the deserialization of untrusted data (CWE-502). An attacker with 'Shop Manager' or higher privileges can provide specially crafted input that, when processed by the plugin, allows for the injection of PHP objects. If a suitable Property-Oriented Programming (POP) chain is present in the environment, this can lead to remote code execution, SQL injection, or file system manipulation. The vulnerability is reachable over the network without user interaction, though it requires high-level authentication. A fix is available in version 5.9.0.

Affected products

  • WP Overnight WooCommerce PDF Invoices & Packing Slips < 5.9.0

Timeline

  • 2026-02-25: other: Reported by researcher daroo
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References