PT-2025-52868 · Automattic+1 · Woocommerce+1

·

CVE-2025-13773

·

Published

2025-12-24

·

Updated

2026-06-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Print Invoice & Delivery Notes for WooCommerce versions up to and including 5.8.0
Description The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is susceptible to Remote Code Execution due to a missing capability check within the WooCommerce Delivery Notes::update function, the presence of PHP enabled in Dompdf, and a lack of proper escaping in the template.php file. This combination allows unauthenticated attackers to potentially execute code on the server. The WooCommerce Delivery Notes::update function is a key component involved in the issue.
Recommendations Versions up to and including 5.8.0 should be updated to a newer, fixed version when available. As a temporary workaround, consider disabling the WooCommerce Delivery Notes::update function until a patch is available.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13773

Affected Products

Print Invoice & Delivery Notes For Woocommerce
Woocommerce