SuperFaktura WooCommerce
SuperFaktura WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Server-Side Request Forgery (SSRF), behind 1 of the records (100%).
The one issue recorded for SuperFaktura WooCommerce has a vendor fix available, so running the current release closes it.
All of these findings were reported by Lucio Sá. SuperFaktura WooCommerce is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-1758SuperFaktura WooCommerce <= 1.40.3 - Authenticated (Subscriber+) Blind Server-Side Request Forgery
Read the full analysisVulnerability Records

SuperFaktura WooCommerce
Author
superfaktura
woocommerceSuperFaktura extension for WooCommerce enables you to create invoices using third-party online app SuperFaktura. SuperFaktura is an online invoicing system for small business owners available in Slovakia (superfaktura.sk) and Czech Republic (superfaktura.cz). For more information about the plugin and its settings check the articles on SuperFaktura blog: SuperFaktúra a WooCommerce: Diel 1. – Inštalácia a autorizácia SuperFaktura a WooCommerce: Díl 1. – Instalace a autorizace Main features of SuperFaktura WooCommerce include: Automatically create invoices in SuperFaktura. Add fields for invoice details to WooCommerce Checkout form. Link to the invoice is added to Customer notification email sent by WooCommerce Order detail WooCommerce My Account page Set your own rules, when proforma or real invoice should be generated. Want to send proforma invoice on order creation and real invoice after payment? We got that covered. Custom invoice numbering. This plugin is not directly associated with superfaktura.sk, s.r.o. or with superfaktura cz, s.r.o. or oficially supported by their developers. Created by Ján Bočínec with the support of Slovak WordPress community and WordPress agency Webikon. Since 2017 maintained by 2day.sk.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C