A code injection vulnerability in the WooCommerce PDF Invoice Builder plugin allows unauthenticated remote attackers to perform remote code inclusion.
Description
A code injection vulnerability in the WooCommerce PDF Invoice Builder plugin allows unauthenticated remote attackers to perform remote code inclusion.
AI Analyst Comment
Remediation
Update Edgar Rojas Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Edgar Rojas
PRODUCT: WooCommerce PDF Invoice Builder
AFFECTED_VERSIONS: n/a through 2.0.8
---END_METADATA---
Description Summary:
A code injection vulnerability in the WooCommerce PDF Invoice Builder plugin allows unauthenticated remote attackers to perform remote code inclusion.
Executive Summary:
A critical remote code inclusion vulnerability in the WooCommerce PDF Invoice Builder plugin permits unauthenticated attackers to execute arbitrary code on the host server.
Vulnerability Details
CVE-ID: CVE-2026-52704
Affected Software: Edgar Rojas WooCommerce PDF Invoice Builder
Affected Versions: n/a through 2.0.8
Vulnerability: This is an Improper Control of Generation of Code vulnerability that facilitates Remote Code Inclusion. The flaw is exploitable by unauthenticated remote attackers, requiring no prior system access or credentials to trigger.
Business Impact
This vulnerability carries a maximum CVSS score of 10.0, representing the highest level of severity. Exploitation allows for complete server takeover, resulting in potential data theft, installation of malicious backdoors, and total loss of confidentiality, integrity, and availability for the affected web store.
Remediation Plan
Immediate Action: Update the WooCommerce PDF Invoice Builder plugin to a version greater than 2.0.8 immediately.
Proactive Monitoring: Audit web server access logs for suspicious requests containing unexpected file paths or code execution payloads directed at the plugin directory.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common code injection and remote file inclusion patterns.
Exploitation Status
Public Exploit Available: True
Analyst Notes: As of Jun 15, 2026, exploitation is confirmed to be easy, remote, and does not require authentication. Immediate remediation is mandatory as the risk of active exploitation is extremely high.
Analyst Recommendation
The availability of public exploit code combined with the unauthenticated nature of this vulnerability necessitates an emergency patching cycle. All instances of the affected plugin must be updated immediately to prevent compromise.