CVE-2025-2942

CVE-2025-2942: Order Delivery Date Pro for WooCommerce < 12.6.0 - Unauthenticated Arbitrary Post Title Disclosure

Vendor Unknown
Product Order Delivery Date
Published July 11, 2025
Last update July 15, 2025

CVSS base score

What the vulnerability does

01Description

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

Key dates

02Disclosure timeline

July 11, 2025 CVE published
July 15, 2025 Record updated