PLUGIN SECURITY
Is Woocommerce Delivery Notes safe?
Create and print PDF invoices, delivery notes, receipts, credit notes, and packing slips for your WooCommerce orders.
What this plugin does
- Slug:
woocommerce-delivery-notes - Author: tychesoftwares
- 30000+ active installs
- 88/100 rating (137 reviews on wordpress.org)
- 1424129 all-time downloads
- On WordPress.org since 2011-12-30
delivery notesinvoicepacking slipspdf invoicewoocommerce print invoice
Maintenance status
- Latest known version: 7.3.0
- Last updated: 2026-08-04 7:04am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
10 known CVEs on file for Woocommerce Delivery Notes. Reported between 2023 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-56060 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 7.1.2 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | High 7.5 | < 7.1.2 | 7.1.2 | 2026-06-25 | ✓ fixed in latest |
| CVE-2026-25317 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 6.0.0 | Missing Authorization | High 7.5 | < 6.0.0 | 6.0.0 | 2026-03-18 | ✓ fixed in latest |
| CVE-2026-24946 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 | Missing Authorization | Medium 6.5 | < 5.9.0 | 5.9.0 | 2026-02-03 | ✓ fixed in latest |
| CVE-2025-13773 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0 | Improper Control of Generation of Code ('Code Injection') | Critical 9.8 | < 5.9.0 | 5.9.0 | 2025-12-23 | ✓ fixed in latest |
| CVE-2025-49239 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.6.0 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 5.6.0 | 5.6.0 | 2025-06-05 | ✓ fixed in latest |
| CVE-2024-13640 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 5.9 | < 5.5.0 | 5.5.0 | 2025-03-07 | ✓ fixed in latest |
| CVE-2024-12210 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.4.1 | Missing Authorization | Medium 4.3 | < 5.4.1 | 5.4.1 | 2024-12-23 | ✓ fixed in latest |
| CVE-2024-4233 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.9.0 | Missing Authorization | Medium 4.3 | < 4.9.0 | 4.9.0 | 2024-04-26 | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2022-46795 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.3 | Missing Authorization | Medium 6.5 | < 4.7.3 | 4.7.3 | 2023-03-13 | ✓ fixed in latest |
| CVE-2023-0479 | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.7.2 | 4.7.2 | 2023-02-02 | ✓ fixed in latest |
| — | Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 4.7.2 | — | Unknown | < 4.7.2 | 4.7.2 | 2023-02-02 | ✓ fixed in latest |
How to fix it
Keep Woocommerce Delivery Notes updated — 7.3.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Bulgarisation for WooCommerce — 5000+ active installs — 100/100 (43) — max PHP <8.0
- Sliced Invoices – WordPress Invoice Plugin — 5000+ active installs — 92/100 (117) — max PHP 8.4
- Timologia for WooCommerce — 3000+ active installs — 94/100 (15) — max PHP 8.4
- SuperFaktura WooCommerce — 2000+ active installs — 98/100 (15)
- PDF Invoices and Packing Slips For WooCommerce — 1000+ active installs — 100/100 (19)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.