CVE-2025-2929: Order Delivery Date Pro for WooCommerce < 12.4.0 - Reflected XSS
The Order Delivery Date WordPress plugin before 12.4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2929?
CVE-2025-2929 has a high severity due to its potential for Reflected Cross-Site Scripting attacks.
How can CVE-2025-2929 be exploited?
CVE-2025-2929 can be exploited by injecting malicious scripts through unsanitized parameters targeted at high privilege users.
How do I fix CVE-2025-2929?
To fix CVE-2025-2929, update the Order Delivery Date for WooCommerce plugin to version 12.4.0 or later where the vulnerability is patched.
Who is affected by CVE-2025-2929?
CVE-2025-2929 affects users of the Order Delivery Date WordPress plugin before version 12.4.0, particularly those with high privilege roles like admin.
Is CVE-2025-2929 specific to certain versions of WordPress?
CVE-2025-2929 is not specific to certain versions of WordPress but affects the Order Delivery Date for WooCommerce plugin versions prior to 12.4.0.