CVE-2025-49239: WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 5.5.0 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce allows Cross Site Request Forgery. This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 5.5.0.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Cross Site Request Forgery.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.5.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49239?
CVE-2025-49239 is classified as a critical Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-49239?
To fix CVE-2025-49239, update the Print Invoice & Delivery Notes for WooCommerce plugin to version 5.5.1 or later.
Which versions are affected by CVE-2025-49239?
CVE-2025-49239 affects all versions of the Print Invoice & Delivery Notes for WooCommerce plugin up to and including version 5.5.0.
What type of vulnerability is CVE-2025-49239?
CVE-2025-49239 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is impacted by CVE-2025-49239?
Users of the Print Invoice & Delivery Notes for WooCommerce plugin versions up to 5.5.0 are impacted by CVE-2025-49239.