Wpovernight develops a focused suite of WooCommerce extensions for invoice management, order forms, and proposal handling that extend e-commerce functionality for small and medium-sized businesses. The vendor's vulnerability profile clusters around web-application input-handling and session-management weaknesses—cross-site scripting, cross-site request forgery, SQL injection, and authentication flaws—that are characteristic of WordPress plugin ecosystems, alongside exposure of sensitive order and customer data. The extensions acquire public exploit tooling with moderate frequency; defenders should apply vendor patches promptly given the direct access these plugins have to financial transaction data and customer records. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpovernight over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24991MEDIUM The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a R | Jan 3, 2022 | 4.8 | 27 | NO | YES |
CVE-2024-22147HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects P | Jan 27, 2024 | 7.2 | 21 | NO | NO |
CVE-2022-2092MEDIUM The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cr | Jul 11, 2022 | 6.1 | 21 | NO | NO |
CVE-2017-18506MEDIUM The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens. | Aug 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-9927HIGH The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is due to the improper | Oct 23, 2024 | 7.2 | 20 | NO | NO |
CVE-2024-3047HIGH The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() funct | May 2, 2024 | 7.2 | 20 | NO | NO |
CVE-2025-24373MEDIUM woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerabi | Feb 4, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-3045MEDIUM The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 du | May 2, 2024 | 6.1 | 19 | NO | NO |
CVE-2022-47148MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. | Mar 1, 2023 | 4.3 | 17 | NO | NO |
CVE-2022-2537MEDIUM The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin pag | Aug 29, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpovernight.
Media articles that mention a CVE ID that affects a product developed by Wpovernight — matched by CVE ID, not by vendor name.