The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/13a87567-2cf7-4bfb-8d63-a8e74950978f/ | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/13a87567-2cf7-4bfb-8d63-a8e74950978f/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Jul 2025, 00:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:tychesoftwares:order_delivery_date_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
References | () https://wpscan.com/vulnerability/13a87567-2cf7-4bfb-8d63-a8e74950978f/ - Exploit, Third Party Advisory | |
CWE | NVD-CWE-noinfo | |
First Time |
Tychesoftwares order Delivery Date For Woocommerce
Tychesoftwares |
15 Jul 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
References | () https://wpscan.com/vulnerability/13a87567-2cf7-4bfb-8d63-a8e74950978f/ - |
15 Jul 2025, 13:14
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Jul 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-11 06:15
Updated : 2025-07-17 00:59
NVD link : CVE-2025-2942
Mitre link : CVE-2025-2942
CVE.ORG link : CVE-2025-2942
JSON object : View
Products Affected
tychesoftwares
- order_delivery_date_for_woocommerce
CWE