
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60083 is a Deserialization of Untrusted Data vulnerability (Object Injection) in the PDF Invoice Builder for WooCommerce WordPress plugin developed by add-ons.org. It affects all versions from n/a through 6.5.0 (NVD) / through 6.3.2 (ENISA/Patchstack). The vulnerability was published on December 18, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 8.8 (High) (Feedly, Patchstack).
The root cause is improper deserialization of untrusted user-supplied data within the plugin, classified as CWE-502 (Deserialization of Untrusted Data), enabling PHP Object Injection (CAPEC-586). An authenticated attacker with low-privilege access (e.g., a subscriber or customer account) can supply a crafted serialized PHP object via a network request, which the plugin deserializes without adequate validation. If a suitable PHP gadget chain exists in the WordPress environment, this can be leveraged to achieve arbitrary code execution, file manipulation, or other malicious outcomes. No specific technical write-up or public PoC code has been identified at this time (Feedly, Patchstack).
Successful exploitation can result in full compromise of confidentiality, integrity, and availability of the affected WordPress site. A low-privileged attacker could execute arbitrary code on the server, access sensitive data (including customer invoices and payment information stored by WooCommerce), modify or delete site content, and potentially pivot to other systems on the same hosting environment. The vulnerability requires no user interaction and is exploitable remotely over the network (Feedly).
/wp-content/plugins/pdf-for-woocommerce/).O:, a:, or s: in request bodies or parameters).__wakeup/__destruct method calls.bash, curl, wget) indicating potential code execution following deserialization.The primary remediation is to update the PDF Invoice Builder for WooCommerce plugin to a version beyond 6.3.2 (per Patchstack) or beyond 6.5.0 (per NVD). Site administrators should also restrict plugin access to trusted users, implement a Web Application Firewall (WAF) rule to detect and block serialized PHP object payloads in requests, and audit the WordPress environment for signs of compromise. Limiting the number of registered user accounts and enforcing strong authentication (e.g., MFA) reduces the attack surface given the low-privilege requirement (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."