Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpovernight

First CVE: Aug 12, 2019Active for: 7 yearsTotal CVEs: 11
21.6
VTI Score
Low

Wpovernight develops a focused suite of WooCommerce extensions for invoice management, order forms, and proposal handling that extend e-commerce functionality for small and medium-sized businesses. The vendor's vulnerability profile clusters around web-application input-handling and session-management weaknesses—cross-site scripting, cross-site request forgery, SQL injection, and authentication flaws—that are characteristic of WordPress plugin ecosystems, alongside exposure of sensitive order and customer data. The extensions acquire public exploit tooling with moderate frequency; defenders should apply vendor patches promptly given the direct access these plugins have to financial transaction data and customer records. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpovernight over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2019
6 years ago
Most Recent CVE
Feb 4, 2025
535 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24991MEDIUM
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a R
Jan 3, 20224.827NOYES
CVE-2024-22147HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects P
Jan 27, 20247.221NONO
CVE-2022-2092MEDIUM
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cr
Jul 11, 20226.121NONO
CVE-2017-18506MEDIUM
The woocommerce-pdf-invoices-packing-slips plugin before 2.0.13 for WordPress has XSS via the tab or section variable on settings screens.
Aug 12, 20196.121NONO
CVE-2024-9927HIGH
The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is due to the improper
Oct 23, 20247.220NONO
CVE-2024-3047HIGH
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() funct
May 2, 20247.220NONO
CVE-2025-24373MEDIUM
woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerabi
Feb 4, 20256.519NONO
CVE-2024-3045MEDIUM
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 du
May 2, 20246.119NONO
CVE-2022-47148MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
Mar 1, 20234.317NONO
CVE-2022-2537MEDIUM
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin pag
Aug 29, 20226.117NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
73%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low1 (9.1%)
High4 (36.4%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpovernight.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpovernight — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpovernight's Products

View all 5 CNAs →

Top CWEs