Browse all 4 CVE security advisories affecting wpovernight. AI-powered Chinese analysis, POCs, and references for each vulnerability.
wpovernight develops WordPress optimization plugins focused on performance and caching. Historically, their products have been susceptible to multiple remote code execution vulnerabilities, often stemming from insufficient input validation and improper file handling. Cross-site scripting (XSS) has also been prevalent, allowing attackers to inject malicious scripts into web pages. Privilege escalation vulnerabilities have been identified in some versions, potentially enabling unauthorized access to administrative functions. While no major public security incidents have been widely reported, the four CVEs on record highlight consistent security challenges in their plugin architecture, emphasizing the need for rigorous input sanitization and secure coding practices.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-1906 | PDF Invoices & Packing Slips for WooCommerce <= 5.6.0 - Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification — PDF Invoices & Packing Slips for WooCommerceCWE-862 | 4.3 | Medium | 2026-02-18 |
| CVE-2025-24373 | Unrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slips — woocommerce-pdf-invoices-packing-slipsCWE-200 | 6.5 | - | 2025-02-04 |
| CVE-2024-3045 | PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting — PDF Invoices & Packing Slips for WooCommerceCWE-79 | 7.2 | High | 2024-05-02 |
| CVE-2024-3047 | PDF Invoices & Packing Slips for WooCommerce <= 3.8.0 - Unauthenticated Server-Side Request Forgery — PDF Invoices & Packing Slips for WooCommerceCWE-918 | 7.2 | High | 2024-05-02 |
This page lists every published CVE security advisory associated with wpovernight. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.