CVE Vulnerabilities

CVE-2025-2942

Published: Jul 11, 2025 | Modified: Jul 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

Affected Software

NameVendorStart VersionEnd Version
Order_delivery_date_for_woocommerceTychesoftwares*12.6.0 (excluding)

References