What the vulnerability does
01Description
Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-location-date-time-free-version allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery & Pickup Location Date Time: from n/a through <= 1.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Order Delivery & Pickup Location Date Time plugin for WordPress does not properly check user permissions before allowing modifications to delivery and pickup settings. An unauthenticated attacker can modify these settings over the network without needing to log in or interact with a site administrator. This affects versions 1.1.0 and earlier.
What an attacker can do
03Attacker Capabilities
Modify delivery and pickup location settings without authentication.
Potential impact on your site
04Site Impact
Attackers can alter your store's delivery and pickup options, disrupting customer orders and operations.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 18, 2024
CVE published
April 28, 2026
Record updated