216.73.216.6

CVE-2025-13773

· Published 24/12/2025 05:16 · Modified 24/12/2025 05:16

Labels: CVE-2025-13773 2025-12-24CVE-2025-13773CWE-94[email protected]

Essential information

Published
24/12/2025 05:16
Modified
24/12/2025 05:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
woocommerce / print invoice delivery notes cpe:2.3:a:woocommerce:print_invoice_delivery_notes:*:*:*:*:*:wordpress:*:*

References