CVE-2025-2942
11.07.2025, 06:15
The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such informationEnginsight
| Vendor | Product | Version |
|---|---|---|
| tychesoftwares | order_delivery_date_for_woocommerce | 𝑥 < 12.6.0 |
𝑥
= Vulnerable software versions