
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67589 is a Missing Authorization (Broken Access Control) vulnerability in the WP Overnight WooCommerce PDF Invoices & Packing Slips WordPress plugin. It affects all versions from n/a through 4.9.1 and was published on December 9, 2025, with Patchstack as the assigning authority. The vulnerability allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, ENISA EUVD).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify that a requesting user has the necessary permissions before executing certain actions or exposing data. This allows a network-adjacent, low-privileged authenticated user (e.g., a subscriber or customer role) to access functionality or data that should be restricted to higher-privileged roles such as shop managers or administrators. No user interaction is required, and attack complexity is low, making exploitation straightforward for any authenticated WordPress user (Feedly, ENISA EUVD).
Successful exploitation results in unauthorized read access to sensitive information (confidentiality impact: Low), with no direct impact on data integrity or system availability. In a WooCommerce context, exposed data could include customer order details, invoice PDFs, or packing slip contents — information that should be restricted to store administrators. The scope is limited to the affected WordPress/WooCommerce installation, with no evidence of lateral movement potential beyond the application layer (Feedly).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-67589 as of the available data. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid (low-privileged) authenticated account on the target WordPress site (Feedly).
Users should update the WooCommerce PDF Invoices & Packing Slips plugin to a version above 4.9.1 (the first patched release). The fix was coordinated and disclosed by Patchstack. As a temporary workaround, site administrators can restrict plugin functionality to trusted roles only or temporarily deactivate the plugin until an update is applied. Regularly auditing WordPress plugin versions and applying updates promptly is the recommended long-term practice (ENISA EUVD, Sucuri Blog).
Sucuri included CVE-2025-67589 in its December 2025 vulnerability patch roundup, highlighting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). No significant independent researcher commentary or notable social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."