The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NTychesoftwares Order Delivery Date For Woocommerce
APPTychesoftwares< 12.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2025-2929HIGH7.1same product
The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputt...
CVE-2023-41874HIGH7.1same product
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooComme...
CVE-2023-41858MEDIUM4.3same product
Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= ...
CVE-2025-2907CRITICAL9.8PL ✓same vendor
CSRF i brak autoryzacji w wtyczce Order Delivery Date Pro for WooCommerce umożliwiają przejęcie witryny
CVE-2023-2986CRITICAL9.8PL ✓same vendor
Authentication bypass w wtyczce Abandoned Cart Lite for WooCommerce