RVCFDI para Woocommerce Security & Risk Analysis

wordpress.org/plugins/rvcfdi-para-woocommerce

El plugin RVCFDI para WooCommerce es una herramienta que se integra con RV Factura Electronica Web y te permite llevar a cabo el proceso facturacion e …

70 active installs v8.1.8 PHP + WP 4.7.3+ Updated Dec 18, 2025
autofacturacioncfdifactura-electronica-mexico
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 9, 2026
Safety Verdict

Is RVCFDI para Woocommerce Safe to Use in 2026?

Mostly Safe

Score 78/100

RVCFDI para Woocommerce is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Feb 9, 2026Updated 3mo ago
Risk Assessment

The static analysis of "rvcfdi-para-woocommerce" v8.1.8 reveals a mixed security posture. While the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having a seemingly small attack surface with no reported AJAX handlers, shortcodes, cron events, or REST API routes without authentication, significant concerns arise from the output escaping and lack of capability checks. The fact that 100% of outputs are not properly escaped is a major red flag, strongly indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of any nonce or capability checks on entry points, if any were present but not detected by the static analysis, would amplify this risk. The vulnerability history, with one unpatched medium severity CVE related to XSS, reinforces these concerns, suggesting a recurring pattern of input sanitization issues. The plugin's overall security is compromised by these critical weaknesses, outweighing its strengths in SQL handling and attack surface management.

Key Concerns

  • 0% output escaping
  • 0 nonce checks
  • 0 capability checks
  • 1 unpatched medium CVE
Vulnerabilities
1

RVCFDI para Woocommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-69386medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RVCFDI para Woocommerce <= 8.1.8 - Reflected Cross-Site Scripting

Feb 9, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

RVCFDI para Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
18
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
22
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped18 total outputs
Attack Surface

RVCFDI para Woocommerce Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

RVCFDI para Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 18, 2025
PHP min version
Downloads12K

Community Trust

Rating76/100
Number of ratings5
Active installs70
Developer Profile

RVCFDI para Woocommerce Developer Profile

realvirtualmx

2 plugins · 80 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RVCFDI para Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rvcfdi-para-woocommerce/css/jquery-ui.css/wp-content/plugins/rvcfdi-para-woocommerce/css/jquery-ui.structure.css/wp-content/plugins/rvcfdi-para-woocommerce/css/jquery-ui.theme.css/wp-content/plugins/rvcfdi-para-woocommerce/css/style.css/wp-content/plugins/rvcfdi-para-woocommerce/js/rvcfdi.js
Script Paths
/wp-content/plugins/rvcfdi-para-woocommerce/js/rvcfdi.js
Version Parameters
rvcfdi-para-woocommerce/css/jquery-ui.css?ver=rvcfdi-para-woocommerce/css/jquery-ui.structure.css?ver=rvcfdi-para-woocommerce/css/jquery-ui.theme.css?ver=rvcfdi-para-woocommerce/css/style.css?ver=rvcfdi-para-woocommerce/js/rvcfdi.js?ver=

HTML / DOM Fingerprints

CSS Classes
rvcfdi-inputrvcfdi-labelrvcfdi-select
HTML Comments
<!-- Begin RVCFDI WooCommerce --><!-- End RVCFDI WooCommerce -->
Data Attributes
data-rvcfdi-fielddata-rvcfdi-options
JS Globals
rvcfdi_params
FAQ

Frequently Asked Questions about RVCFDI para Woocommerce