Skip to main content
Mallory
Critical

Remote Code Inclusion in WooCommerce PDF Invoice Builder through 2.0.8

IdentifiersCVE-2026-52704CWE-94· Improper Control of Generation of…

CVE-2026-52704 is an improper control of generation of code vulnerability in the WooCommerce PDF Invoice Builder WordPress plugin by Edgar Rojas. The available description states that the flaw allows remote code inclusion and affects WooCommerce PDF Invoice Builder through version 2.0.8. Based on the provided classification, the issue maps to CWE-94 and indicates that attacker-controlled input is insufficiently constrained in a code-generation or code-loading path, resulting in inclusion and execution of remote code. No specific vulnerable function, parameter, or execution path was provided in the available content.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow an unauthenticated remote attacker to cause execution of attacker-controlled code in the context of the vulnerable WordPress application or underlying web server process. The provided CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) indicates high impact to confidentiality, integrity, and availability, with no privileges or user interaction required and a changed scope. This can plausibly result in full site compromise, theft or modification of WordPress and WooCommerce data, arbitrary file or database manipulation, installation of persistent backdoors, and service disruption.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, disable the WooCommerce PDF Invoice Builder plugin to eliminate exposure. Restrict public access to the affected WordPress instance or place administrative and plugin-exposed endpoints behind network access controls where feasible. Deploy WAF rules or virtual patching to block suspicious requests targeting the plugin, especially requests attempting remote file inclusion or attacker-controlled path/code parameters. Monitor web server, PHP, and WordPress logs for exploitation attempts and review the environment for unauthorized files, modified plugin/theme code, rogue administrator accounts, and unexpected outbound connections.

Remediation

Patch, then assume compromise.

Update WooCommerce PDF Invoice Builder to a fixed version newer than 2.0.8 if one is available from the vendor. If no patched release is yet available, remove or disable the plugin until a fix is published. Review vendor or Patchstack advisories for the exact patched version and any additional hardening guidance. After remediation, inspect the WordPress instance for indicators of compromise because the vulnerability is described as remotely exploitable without authentication.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity6

Community discussion across Reddit, Mastodon, and other social sources.