/Vulnerability Library

WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code Execution

CVE-2025-13773
Verified

Description

Print Invoice & Delivery Notes for WooCommerce plugin for WordPress <= 5.8.0 contains a remote code execution caused by missing capability check, PHP enabled in Dompdf, and missing escape in template.php, letting unauthenticated attackers execute code on the server.

Severity

Critical

CVSS Score

9.8

Exploit Probability

4%

Affected Product

woocommerce-delivery-notes

Published Date

May 14, 2026

Template Author

pikajuna-ops

CVE-2025-13773.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-13773
CWE ID:
cwe-94

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/e52b34fe-2414-4d6f-bf43-9c5b65ebf769https://plugins.trac.wordpress.org/changeset/3426119/woocommerce-delivery-noteshttps://nvd.nist.gov/vuln/detail/CVE-2025-13773

Remediation Steps

Update to the latest version beyond 5.8.0.