← Back to Research Blog
CRITICAL CVE-2026-52704

Critical Remote Code Execution Vulnerability in WooCommerce PDF Invoice Builder Exposes Enterprise WordPress Sites

10.0
CRITICAL
woocommerce-pdf-invoice-builder, wordpre
2026-08-11

Overview

A high-severity code injection vulnerability (CVE-2026-52704) in the WooCommerce PDF Invoice Builder plugin for WordPress allows remote code execution with critical 10.0 CVSS impact. Unpatched systems face imminent risk of full infrastructure compromise.


Technical Analysis

The vulnerability arises from unchecked dynamic code generation in invoice templates, enabling attackers to inject and execute arbitrary PHP code via specially crafted invoice generation requests. Exploitation requires no authentication and can be triggered through the /invoice-builder endpoint using URL-encoded payloads. The flaw's reliability stems from improper input validation during template rendering, allowing attackers to bypass standard WordPress security filters. Successful exploitation grants full server access for lateral movement and persistent access establishment.

Enterprise & DIB Impact

Defense Industrial Base contractors and enterprises relying on WordPress for customer portals or e-commerce face existential risk, as breach could compromise sensitive operational data, CUI systems, and supply chain networks. The plugin's presence in 49,000+ WordPress installations expands the potential attack surface, including systems storing classified information under DIB requirements.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512