Cross-Site Request Forgery Vulnerability in Flexible PDF Invoices for WooCommerce by WP Desk
CVE-2025-57977
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2025
What is CVE-2025-57977?
The Cross-Site Request Forgery vulnerability in Flexible PDF Invoices for WooCommerce poses a significant risk, allowing attackers to trick users into performing actions without their consent. This weakness affects versions up to 6.0.13 and highlights the importance of implementing security measures to protect WordPress sites using this plugin. Website owners should promptly update their installations to safeguard against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Flexible PDF Invoices for WooCommerce & WordPress <= 6.0.13
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
theviper17 (Patchstack Alliance)