Extension WordPress

Vulnérabilités PDF Invoice for WooCommerce + Drag and Drop Template Builder

Cette page rassemble les failles publiées pour PDF Invoice for WooCommerce + Drag and Drop Template Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
0Critiques
3Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de PDF Invoice for WooCommerce + Drag and Drop Template Builder

3 fiches

CVE-2025-60083 Élevée · 8,8
PDF Invoice for WooCommerce + Drag and Drop Template Builder

PDF Invoice Builder for WooCommerce <= 6.5.0 – Authenticated (Subscriber+) PHP Object Injection

The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.0 via deserialization of untrusted input. This makes it possible for…

Versions affectées

*-6.5.0

Correctif

6.5.1

Publication

23/08/2025

CVE-2025-47537 Moyenne · 4,9
PDF Invoice for WooCommerce + Drag and Drop Template Builder

PDF Invoices for WooCommerce + Drag and Drop Template Builder <= 5.3.8 – Authenticated (Administrator+) SQL Injection

The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.3.8 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-5.3.8

Correctif

5.4.0

Publication

07/05/2025

CVE-2025-24755 Moyenne · 6,4
PDF Invoice for WooCommerce + Drag and Drop Template Builder

PDF Invoices for WooCommerce + Drag and Drop Template Builder <= 4.6.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-4.6.0

Correctif

4.7.0

Publication

24/01/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités