PatchSiren

WP Overnight CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WP Overnight CVE published 2026-06-15

CVE-2026-39472

CVE-2026-39472 is a HIGH severity vulnerability in WooCommerce PDF Invoices & Packing Slips plugin versions less than 5.9.0. The vulnerability is caused by a PHP Object Injection issue that can be exploited by shop managers. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.2.