WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code Execution
CVE-2025-13773
Verified
Description
Print Invoice & Delivery Notes for WooCommerce plugin for WordPress <= 5.8.0 contains a remote code execution caused by missing capability check, PHP enabled in Dompdf, and missing escape in template.php, letting unauthenticated attackers execute code on the server.
Severity
Critical
CVSS Score
9.8
Exploit Probability
4%
Affected Product
woocommerce-delivery-notes
Published Date
May 14, 2026
Template Author
pikajuna-ops
CVE-2025-13773.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-13773
CWE ID:
cwe-94
Remediation Steps
Update to the latest version beyond 5.8.0.