The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Order_delivery_date_for_woocommerce | Tychesoftwares | * | 12.6.0 (excluding) |