PoC Index

CVE-2025-13773

CRITICAL 9.8EPSS 3.8%

The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in Dompdf, and missing escape in the 'template.php' file. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.77% chance of exploitation in the next 30 days, 89th percentile
Nuclei
critical · CWE-94
Published
2025-12-24
Updated
2026-04-08

Nuclei templates (1)

References

Related