CVE · Medium

CVE-2025-67589 — PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.0.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-67589 PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.0.0 Missing Authorization Medium 4.3 < 5.0.0 5.0.0 2025-12-07

CVE-2025-67589

A security flaw exists within the PDF Invoices & Packing Slips plugin for WordPress, where insufficient permission checks allow users with elevated roles to bypass intended restrictions on a specific function in versions prior to 4.9.2. This oversight enables attackers with Contributor-level access or higher to execute unauthorized actions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.