The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
History

Thu, 17 Jul 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Tychesoftwares
Tychesoftwares order Delivery Date For Woocommerce
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:tychesoftwares:order_delivery_date_for_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Tychesoftwares
Tychesoftwares order Delivery Date For Woocommerce

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}

epss

{'score': 0.00028}


Tue, 15 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}


Fri, 11 Jul 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
Title Order Delivery Date Pro for WooCommerce < 12.6.0 - Unauthenticated Arbitrary Post Title Disclosure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-07-11T06:00:02.439Z

Updated: 2025-07-15T13:47:22.514Z

Reserved: 2025-03-28T20:52:11.309Z

Link: CVE-2025-2942

cve-icon Vulnrichment

Updated: 2025-07-15T13:46:04.898Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-11T06:15:22.977

Modified: 2025-07-17T00:59:53.223

Link: CVE-2025-2942

cve-icon Redhat

No data.