Executive brief
A critical security flaw exists in the WooCommerce PDF Invoice Builder plugin, which is used by online stores to generate customer invoices. This vulnerability allows an attacker to remotely take full control of the website without needing any login credentials. Such an exploit could lead to the theft of customer data, complete website defacement, or the installation of malicious software on the server.
Technical details
A Remote Code Execution (RCE) vulnerability exists in the Edgar Rojas WooCommerce PDF Invoice Builder plugin for WordPress due to improper control of code generation (CWE-94). The flaw allows an unauthenticated remote attacker to inject and execute arbitrary PHP code on the server. This is achieved via a network-based attack vector with low complexity and no user interaction required. Successful exploitation grants the attacker full control over the affected WordPress environment. The issue is resolved in version 2.0.9.
Affected products
- Edgar Rojas WooCommerce PDF Invoice Builder n/a through 2.0.8
Timeline
- 2026-05-25: other: Reported by researcher she11f
- 2026-06-15: disclosed: Vulnerability published by Patchstack and NVD
- 2026-06-15: patched: Version 2.0.9 released to address the vulnerability