CVE 9.8 CRITICAL

Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Unauthenticated Remote Code Execution_CVE-2025-13773

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.

AI Analysis

Unauthenticated Remote Code Execution vulnerability in Print Invoice & Delivery Notes for WooCommerce plugin due to missing capability check and PHP enabled in Dompdf

Basic Information

ID CVE-2025-13773
Source Wordfence
Published Dec 24, 2025 at 04:32

Affected Product

Vendor tychesoftwares
Product Print Invoice & Delivery Notes for WooCommerce
Version *
Affected Versions tychesoftwares Print Invoice & Delivery Notes for WooCommerce *

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor tychesoftwares
Product Print Invoice & Delivery Notes for WooCommerce
Version 5.8.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.