Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

edgarrojas — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting edgarrojas. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Edgarrojas primarily focuses on web application security research, identifying vulnerabilities in popular software and frameworks. Historically, their contributions center on remote code execution, cross-site scripting, and privilege escalation flaws, particularly in content management systems and e-commerce platforms. Their work has led to 14 CVE assignments, with several critical findings in widely used plugins and themes. While no major public security incidents are directly attributed to their research, their discoveries have consistently addressed high-impact vulnerabilities affecting real-world deployments. Their profile demonstrates a consistent pattern of uncovering flaws that could lead to complete system compromise or data breaches in affected applications.

CVE ID Title CVSS Severity Published
CVE-2026-11899 PDF Builder for WooCommerce. Create invoices,packing slips and more <= 2.0.11 - Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-862 4.3 Medium 2026-09-19
CVE-2026-11496 Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-862 6.5 Medium 2026-09-11
CVE-2026-57393 WordPress WooCommerce PDF Invoice Builder plugin <= 2.0.8 - Sensitive Data Exposure vulnerability — WooCommerce PDF Invoice Builder CWE-497 6.5 Medium 2026-07-13
CVE-2026-57390 WordPress Extra Product Options Builder for WooCommerce plugin <= 1.2.167 - Broken Access Control vulnerability — Extra Product Options Builder for WooCommerce CWE-862 6.5 Medium 2026-07-13
CVE-2026-2022 Smart Forms <= 2.6.99 - Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure — Smart Forms – when you need more than just a contact form CWE-862 4.3 Medium 2026-02-14
CVE-2025-64269 WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.150 - Broken Access Control vulnerability — WooCommerce PDF Invoice Builder CWE-862 4.3 Medium 2025-11-13
CVE-2025-11889 AIO Forms <= 1.3.18 - Authenticated (Admin+) Arbitrary File Upload via Zip Import — AIO Forms – Craft Complex Forms Easily CWE-434 7.2 High 2025-10-24
CVE-2025-53203 WordPress WooCommerce PDF Invoice Builder plugin <= 1.2.148 - Cross Site Request Forgery (CSRF) Vulnerability — WooCommerce PDF Invoice Builder CWE-352 4.3 Medium 2025-06-27
CVE-2025-5055 Smart Forms <= 2.6.98 - Authenticated (Admin+) Stored Cross-Site Scripting — Smart Forms – when you need more than just a contact form CWE-79 4.4 Medium 2025-05-24
CVE-2023-49856 WordPress Smart Forms plugin <= 2.6.84 - Authenticated Arbitrary Options Change Vulnerability — Smart Forms CWE-862 8.1 High 2024-12-09
CVE-2024-11276 PDF Builder for WooCommerce. Create invoices,packing slips and more <= 1.2.136 - Reflected Cross-Site Scripting — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-79 6.1 Medium 2024-12-06
CVE-2024-9214 Extra Product Options Builder for WooCommerce <= 1.2.133 - Unauthenticated Stored Cross-Site Scripting — Extra Product Options Builder for WooCommerce CWE-79 6.1 Medium 2024-10-24
CVE-2024-7414 PDF Builder for WPForms <= 1.2.116 - Unauthenticated Full Path Disclosure — PDF Builder for WPForms CWE-200 5.3 Medium 2024-08-09
CVE-2023-3764 WooCommerce PDF Invoice Builder <= 1.2.90 - Cross-Site Request Forgery via Save — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-352 4.3 Medium 2023-08-31
CVE-2023-4160 WooCommerce PDF Invoice Builder <= 1.2.90 - Authenticated (Administrator+) Cross-Site Scripting — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-79 4.4 Medium 2023-08-31
CVE-2023-3677 WooCommerce PDF Invoice Builder <= 1.2.89 - Authenticated (Subscriber+) SQL Injection via Export — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-89 8.8 High 2023-08-31
CVE-2023-4161 WooCommerce PDF Invoice Builder <= 1.2.90 - Cross-Site Request Forgery to Custom Field Creation — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-352 4.3 Medium 2023-08-31
CVE-2023-4245 WooCommerce PDF Invoice Builder <= 1.2.89 - Missing Authorization to Sensitive Information Exposure — PDF Builder for WooCommerce. Create invoices,packing slips and more CWE-862 4.3 Medium 2023-08-31

This page lists every published CVE security advisory associated with edgarrojas. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.