CVE-2025-60083
8.8add-ons.org · PDF Invoice Builder for WooCommerce
The PDF Invoice Builder for WooCommerce plugin contains a deserialization of untrusted data flaw that allows remote attackers to perform object injection attacks.
Executive summary
The PDF Invoice Builder for WooCommerce plugin is vulnerable to object injection, which could allow an authenticated attacker to achieve remote code execution.
Vulnerability
This vulnerability is a deserialization of untrusted data (CWE-502) affecting the plugin, which allows an authenticated attacker with low privileges to perform object injection. The attack vector is network-based and does not require user interaction.
Business impact
The ability to perform object injection can lead to complete compromise of the affected application, including unauthorized data access, modification, and potential remote code execution. With a CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it could facilitate significant data breaches or service disruption if left unaddressed.
Remediation
Immediate Action: Since no specific patch version is currently identified, administrators should monitor the vendor advisory for the release of an update and apply it immediately upon availability.
Proactive Monitoring: Security teams should monitor server access logs for suspicious serialized objects or unusual payload strings originating from authenticated users.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common deserialization attack patterns or malicious object injection attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS severity and the potential for full system compromise, this vulnerability should be treated with high priority. Organizations currently utilizing the PDF Invoice Builder for WooCommerce plugin must restrict administrative access where possible and remain vigilant for vendor security updates. Applying the pending patch is the only definitive way to mitigate this risk.
Sources
Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.