CVE-2025-60083

8.8

add-ons.org · PDF Invoice Builder for WooCommerce

The PDF Invoice Builder for WooCommerce plugin contains a deserialization of untrusted data flaw that allows remote attackers to perform object injection attacks.

Executive summary

The PDF Invoice Builder for WooCommerce plugin is vulnerable to object injection, which could allow an authenticated attacker to achieve remote code execution.

Vulnerability

This vulnerability is a deserialization of untrusted data (CWE-502) affecting the plugin, which allows an authenticated attacker with low privileges to perform object injection. The attack vector is network-based and does not require user interaction.

Business impact

The ability to perform object injection can lead to complete compromise of the affected application, including unauthorized data access, modification, and potential remote code execution. With a CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it could facilitate significant data breaches or service disruption if left unaddressed.

Remediation

Immediate Action: Since no specific patch version is currently identified, administrators should monitor the vendor advisory for the release of an update and apply it immediately upon availability.

Proactive Monitoring: Security teams should monitor server access logs for suspicious serialized objects or unusual payload strings originating from authenticated users.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common deserialization attack patterns or malicious object injection attempts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS severity and the potential for full system compromise, this vulnerability should be treated with high priority. Organizations currently utilizing the PDF Invoice Builder for WooCommerce plugin must restrict administrative access where possible and remain vigilant for vendor security updates. Applying the pending patch is the only definitive way to mitigate this risk.

Sources

Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.