CVE-2026-52704Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-15); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-15: 2Mentions · 2026-06-16: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-06-15: 2Technical Details · 2026-06-16: 106-1506-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-152
Disclosure1Patch1
2026-06-161
Disclosure1
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Vulnerabilities in Wordpress WooCommerce and OttoKit plugins. #CVE-2026-52704 (CVSS 10.0) a Remote Code Execution vulnerability affecting WooCommerce PDF Invoice Builder. #CVE-2026-49781(9.8) an unauthenticated PHP Object Injection in the OttoKit. #Patch #Patch #RCE

    Post summary

    The tweet announces two critical CVEs affecting WordPress plugins, providing their IDs, CVSS scores, and types but lacking exploit or patch details.

    01000226
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52704 Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affec… https://www.cve.org/CVERecord?id=CVE-2026-52704

    Post summary

    This brief notice announces CVE‑2026‑52704, a code injection vulnerability in the WooCommerce PDF Invoice Builder that could allow remote code inclusion, but it offers no PoC, exploit details, or mitigation information.

    00000125
    57.6K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🧾 CVSS 10 RCE in WooCommerce PDF Invoice Builder (<=2.0.8). No auth needed, full code injection via remote file inclusion. If this plugin is in your stack, update immediately. CVE-2026-52704 https://secalerts.co/vulnerability/CVE-2026-52704 https://t.co/05xiNQhjh5

    Post summary

    A critical remote code execution vulnerability (CVE‑2026‑52704) exists in WooCommerce PDF Invoice Builder <=2.0.8 via remote file inclusion; users are urged to update immediately to mitigate the risk.

    0000060
    835 followersView on X

Explore more