Home
CRITICAL: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
Any version
affected
Description
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version
Credits
she11f | Patchstack Bug Bounty Program
References
patchstack.com/...code-execution-rce-vulnerability?_s_id=cve