CVE-2026-39472: Wp Overnight Woocommerce PDF Invoices & Packing Slips

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

Affected products

  • Wp Overnight Woocommerce PDF Invoices & Packing Slips: before 5.9.0 (fixed in 5.9.0)

Published 2026-06-15. Last modified 2026-06-17.