10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion.
This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
AI Analysis
Remote Code Execution (RCE) vulnerability in WooCommerce PDF Invoice Builder plugin due to improper control of code generation
Basic Information
ID
CVE-2026-52704
Source
Patchstack
Published
Jun 15, 2026 at 12:49
Modified
Jun 15, 2026 at 12:54
Affected Product
Vendor
Edgar Rojas
Product
WooCommerce PDF Invoice Builder
Version
n/a
Affected Versions
Edgar Rojas WooCommerce PDF Invoice Builder n/a
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Edgar Rojas
Product
WooCommerce PDF Invoice Builder
Version
2.0.8