SECURITYHIGHCVE-2026-92244

CVE-2026-92244: Unauthenticated Stored XSS in WooCommerce PDF Invoices Plugin

High-severity stored XSS (CVSS 7.2) in PDF Invoices & Packing Slips for WooCommerce, 300K+ sites, triggered via guest checkout fields.

Dylan H.

Security Team

October 2, 2026
6 min read
CVE-2026-92244: Unauthenticated Stored XSS in WooCommerce PDF Invoices Plugin

Affected Products

  • PDF Invoices & Packing Slips for WooCommerce (print-invoices-packing-slip-labels-for-woocommerce), versions through 5.16.1

Overview

CVE-2026-92244 is a high-severity stored cross-site scripting (XSS) vulnerability in PDF Invoices & Packing Slips for WooCommerce (plugin slug print-invoices-packing-slip-labels-for-woocommerce, published by WP Overnight), a WordPress/WooCommerce add-on with 300,000+ active installations used to generate branded invoices, packing slips, delivery notes, and shipping labels for WooCommerce orders. The flaw affects all versions through 5.16.1 and was published October 1, 2026, with a fix shipped in 5.16.2.

Per NVD and corroborating entries from WPScan and Patchstack, the plugin fails to adequately sanitize and escape the Billing First Name, Last Name, and Company fields on WooCommerce orders. Because these fields are populated at checkout, and WooCommerce's guest checkout flow requires no account or authentication, an unauthenticated remote attacker can plant a malicious payload simply by placing an order — no credentials, no social engineering, no victim interaction beyond a store admin or staff member later viewing the tainted order, invoice, or packing slip.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-92244
SeverityHigh
CVSS v3.1 Score7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
CWECWE-79 — Improper Neutralization of Input During Web Page Generation (Cross-Site Scripting)
Affected ComponentBilling First Name / Last Name / Company fields on WooCommerce orders
Attack VectorNetwork, via unauthenticated guest checkout
Authentication RequiredNone
User Interaction RequiredNone by the attacker; a victim (admin/staff) viewing the affected order triggers execution
Installed Base300,000+ active sites (per WPScan/Sucuri)
Public Exploit / PoCNone known at disclosure
CISA KEV ListedNo
Fixed In5.16.2

Technical Details

Root cause

The plugin's order-rendering code — used when generating admin-facing invoices, packing slips, and order views — outputs the Billing First Name, Last Name, and Company fields without sufficient output escaping. WooCommerce's own sanitization helpers, sanitize_text_field() and wc_clean(), strip literal < characters from input but do not strip HTML-entity-encoded payloads that contain no literal angle bracket at write time. Third-party analysis of the patch diff indicates an attacker can craft a payload using entity-encoded markup that survives WooCommerce's input sanitization on write, and is then decoded and rendered unescaped when the plugin later outputs those fields into an invoice, packing slip, or admin order screen — at which point the browser executes it as a stored XSS.

Exploitation path

Attacker (unauthenticated, no account required)
  -> Places a WooCommerce guest-checkout order
    -> Billing First Name / Last Name / Company field contains
       an entity-encoded XSS payload (bypasses sanitize_text_field() / wc_clean())
      -> Payload stored unmodified in the order record
        -> Store admin/staff opens the order, generates an invoice,
           or views the packing slip in wp-admin
          -> Plugin renders the field without output escaping
            -> Payload decodes and executes as JavaScript in the admin's
               browser session (session/cookie theft, admin account
               takeover, further store compromise)

CVSS breakdown

The 7.2 score reflects:

  • Attack Vector: Network — reachable via the storefront's public checkout
  • Attack Complexity: Low — no special conditions beyond placing an order
  • Privileges Required: None — exploitable by anonymous guest-checkout customers
  • User Interaction: None (UI:N) — the CVSS vector treats the triggering admin view as part of normal operation rather than a required interaction step
  • Scope: Changed (S:C) — the vulnerable component (checkout field storage) is distinct from the impacted component (admin-rendered order views)
  • Confidentiality / Integrity Impact: Low — consistent with a stored XSS executing in an authenticated admin context rather than a direct data-exfiltration primitive

Impact Assessment

Impact AreaDescription
ConfidentialityA successful payload executing in a logged-in admin's browser can exfiltrate session cookies, nonces, or other sensitive data visible in wp-admin
IntegrityScript execution in an admin context can be chained into further actions the admin is authorized to perform (plugin installs, user creation, content changes) depending on what the payload does
AvailabilityNot directly impacted (A:N)
Attack SurfacePre-authentication — any site accepting guest checkout is exposed without requiring the attacker to register or log in
Scale300,000+ active installations of the plugin, concentrated among small-to-midsize WooCommerce stores that rely on it for invoicing

Affected Systems

Product / VersionStatus
PDF Invoices & Packing Slips for WooCommerce ≤ 5.16.1Affected
PDF Invoices & Packing Slips for WooCommerce 5.16.2+Not affected (fixed)

Remediation

For WooCommerce store operators

  1. Update to version 5.16.2 or later immediately. Given the unauthenticated, guest-checkout attack vector, this should not wait for a routine plugin-update cycle.
  2. Review recent orders placed before patching for suspicious content in billing name/company fields — particularly orders containing HTML entities, encoded angle brackets, or script-like strings.
  3. Rotate admin session cookies / force re-authentication for store administrators if a suspicious order was opened or an invoice generated from it prior to patching.

For security teams

  1. Treat any WooCommerce add-on that renders customer-supplied checkout fields in admin-facing views as a potential stored-XSS surface, independent of this specific CVE.
  2. Apply a Web Application Firewall (WAF) rule to flag entity-encoded script payloads in checkout billing fields as an interim mitigation where immediate patching isn't possible.
  3. Restrict wp-admin access to trusted networks/VPN where feasible, reducing the blast radius of an admin-session-hijacking payload even if a tainted order is opened.

Key Takeaways

  1. CVE-2026-92244 is a CVSS 7.2 High stored XSS in PDF Invoices & Packing Slips for WooCommerce, affecting all versions through 5.16.1 and fixed in 5.16.2.
  2. The flaw is exploitable by unauthenticated attackers through WooCommerce's guest checkout — no account or prior access is needed to plant the payload.
  3. Root cause: WooCommerce's sanitize_text_field() / wc_clean() sanitizers don't strip entity-encoded payloads lacking a literal angle bracket, letting malicious billing-field content survive storage and later render unescaped.
  4. The plugin has a 300,000+ install base, and the payload executes when a store admin or staff member views the tainted order, invoice, or packing slip.
  5. No public PoC and no CISA KEV listing exist as of disclosure, but the pre-authentication vector warrants prompt patching rather than routine-cycle treatment.
  6. Update to 5.16.2+ immediately, and review orders placed prior to patching for suspicious billing-field content.

Sources