Overview
CVE-2026-92244 is a high-severity stored cross-site scripting (XSS) vulnerability in PDF Invoices & Packing Slips for WooCommerce (plugin slug print-invoices-packing-slip-labels-for-woocommerce, published by WP Overnight), a WordPress/WooCommerce add-on with 300,000+ active installations used to generate branded invoices, packing slips, delivery notes, and shipping labels for WooCommerce orders. The flaw affects all versions through 5.16.1 and was published October 1, 2026, with a fix shipped in 5.16.2.
Per NVD and corroborating entries from WPScan and Patchstack, the plugin fails to adequately sanitize and escape the Billing First Name, Last Name, and Company fields on WooCommerce orders. Because these fields are populated at checkout, and WooCommerce's guest checkout flow requires no account or authentication, an unauthenticated remote attacker can plant a malicious payload simply by placing an order — no credentials, no social engineering, no victim interaction beyond a store admin or staff member later viewing the tainted order, invoice, or packing slip.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-92244 |
| Severity | High |
| CVSS v3.1 Score | 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) |
| CWE | CWE-79 — Improper Neutralization of Input During Web Page Generation (Cross-Site Scripting) |
| Affected Component | Billing First Name / Last Name / Company fields on WooCommerce orders |
| Attack Vector | Network, via unauthenticated guest checkout |
| Authentication Required | None |
| User Interaction Required | None by the attacker; a victim (admin/staff) viewing the affected order triggers execution |
| Installed Base | 300,000+ active sites (per WPScan/Sucuri) |
| Public Exploit / PoC | None known at disclosure |
| CISA KEV Listed | No |
| Fixed In | 5.16.2 |
Technical Details
Root cause
The plugin's order-rendering code — used when generating admin-facing invoices, packing slips, and order views — outputs the Billing First Name, Last Name, and Company fields without sufficient output escaping. WooCommerce's own sanitization helpers, sanitize_text_field() and wc_clean(), strip literal < characters from input but do not strip HTML-entity-encoded payloads that contain no literal angle bracket at write time. Third-party analysis of the patch diff indicates an attacker can craft a payload using entity-encoded markup that survives WooCommerce's input sanitization on write, and is then decoded and rendered unescaped when the plugin later outputs those fields into an invoice, packing slip, or admin order screen — at which point the browser executes it as a stored XSS.
Exploitation path
Attacker (unauthenticated, no account required)
-> Places a WooCommerce guest-checkout order
-> Billing First Name / Last Name / Company field contains
an entity-encoded XSS payload (bypasses sanitize_text_field() / wc_clean())
-> Payload stored unmodified in the order record
-> Store admin/staff opens the order, generates an invoice,
or views the packing slip in wp-admin
-> Plugin renders the field without output escaping
-> Payload decodes and executes as JavaScript in the admin's
browser session (session/cookie theft, admin account
takeover, further store compromise)
CVSS breakdown
The 7.2 score reflects:
- Attack Vector: Network — reachable via the storefront's public checkout
- Attack Complexity: Low — no special conditions beyond placing an order
- Privileges Required: None — exploitable by anonymous guest-checkout customers
- User Interaction: None (
UI:N) — the CVSS vector treats the triggering admin view as part of normal operation rather than a required interaction step - Scope: Changed (
S:C) — the vulnerable component (checkout field storage) is distinct from the impacted component (admin-rendered order views) - Confidentiality / Integrity Impact: Low — consistent with a stored XSS executing in an authenticated admin context rather than a direct data-exfiltration primitive
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | A successful payload executing in a logged-in admin's browser can exfiltrate session cookies, nonces, or other sensitive data visible in wp-admin |
| Integrity | Script execution in an admin context can be chained into further actions the admin is authorized to perform (plugin installs, user creation, content changes) depending on what the payload does |
| Availability | Not directly impacted (A:N) |
| Attack Surface | Pre-authentication — any site accepting guest checkout is exposed without requiring the attacker to register or log in |
| Scale | 300,000+ active installations of the plugin, concentrated among small-to-midsize WooCommerce stores that rely on it for invoicing |
Affected Systems
| Product / Version | Status |
|---|---|
| PDF Invoices & Packing Slips for WooCommerce ≤ 5.16.1 | Affected |
| PDF Invoices & Packing Slips for WooCommerce 5.16.2+ | Not affected (fixed) |
Remediation
For WooCommerce store operators
- Update to version 5.16.2 or later immediately. Given the unauthenticated, guest-checkout attack vector, this should not wait for a routine plugin-update cycle.
- Review recent orders placed before patching for suspicious content in billing name/company fields — particularly orders containing HTML entities, encoded angle brackets, or script-like strings.
- Rotate admin session cookies / force re-authentication for store administrators if a suspicious order was opened or an invoice generated from it prior to patching.
For security teams
- Treat any WooCommerce add-on that renders customer-supplied checkout fields in admin-facing views as a potential stored-XSS surface, independent of this specific CVE.
- Apply a Web Application Firewall (WAF) rule to flag entity-encoded script payloads in checkout billing fields as an interim mitigation where immediate patching isn't possible.
- Restrict wp-admin access to trusted networks/VPN where feasible, reducing the blast radius of an admin-session-hijacking payload even if a tainted order is opened.
Key Takeaways
- CVE-2026-92244 is a CVSS 7.2 High stored XSS in PDF Invoices & Packing Slips for WooCommerce, affecting all versions through 5.16.1 and fixed in 5.16.2.
- The flaw is exploitable by unauthenticated attackers through WooCommerce's guest checkout — no account or prior access is needed to plant the payload.
- Root cause: WooCommerce's
sanitize_text_field()/wc_clean()sanitizers don't strip entity-encoded payloads lacking a literal angle bracket, letting malicious billing-field content survive storage and later render unescaped. - The plugin has a 300,000+ install base, and the payload executes when a store admin or staff member views the tainted order, invoice, or packing slip.
- No public PoC and no CISA KEV listing exist as of disclosure, but the pre-authentication vector warrants prompt patching rather than routine-cycle treatment.
- Update to 5.16.2+ immediately, and review orders placed prior to patching for suspicious billing-field content.