EDGARROJAS has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 6.5 (medium). Most affected products: PDF Builder for WooCommerce. Create invoices,packing slips and more (2), smart-forms (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Products
- PDF Builder for WooCommerce. Create invoices,packing slips and more 2
- smart-forms 1
Worst active — by depth score
CVE-2026-32574High· 7.1Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.39CVE-2026-11496Medium· 6.5Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure36CVE-2026-11899Medium· 4.3The PDF Builder for WooCommerce24
EDGARROJAS vulnerabilities
CVEs affecting EDGARROJAS, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-32574High· 7.1Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Forms <= 2.6.104 versions.
CVE-2026-11899Medium· 4.3The PDF Builder for WooCommerce
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user…
CVE-2026-11496Medium· 6.5Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure
The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX ha…