CVE-2025-2942: Order Delivery Date Pro for WooCommerce < 12.6.0 - Unauthenticated Arbitrary Post Title Disclosure
Published Jul 11, 2025
·Updated
The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
Affected Software
2 affected components
WooCommerce Order Delivery Date Pro for WooCommerce<12.6.0
tychesoftwares Order Delivery Date For Woocommerce Wordpress<12.6.0
Event History
Jul 11, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2942?
CVE-2025-2942 is considered a moderate severity vulnerability that allows unauthorized access to post titles.
2
How do I fix CVE-2025-2942?
To fix CVE-2025-2942, update the Order Delivery Date plugin to version 12.6.0 or later.
3
What types of information can be disclosed by CVE-2025-2942?
CVE-2025-2942 can disclose arbitrary post titles, including those from draft and private posts.
4
Who is affected by CVE-2025-2942?
Users of the Order Delivery Date plugin for WooCommerce versions prior to 12.6.0 are affected by CVE-2025-2942.
5
Is CVE-2025-2942 an authenticated vulnerability?
No, CVE-2025-2942 allows information disclosure through an unauthenticated AJAX action.