CVE Vulnerabilities

CVE-2025-2942

Published: Jul 11, 2025 | Modified: Jul 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

Affected Software

Name Vendor Start Version End Version
Order_delivery_date_for_woocommerce Tychesoftwares * 12.6.0 (excluding)

References