← Back to browse · API

CVE-2025-13773

Severity
CRITICAL
CVSS
9.8
EPSS
0.03525
Risk score
40.43
CISA KEV
No
PoC
No
Published
2025-12-24
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-205036, GHSA-9956-2FV5-M3GF
Products
tychesoftwares:Print Invoice & Delivery Notes for WooCommerce 0 ≤5.8.0
Sources
euvd EUVD-2025-205036

Description

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.

References