WordPress Plugin Vulnerabilities

Order Delivery Date Pro for WooCommerce < 12.6.0 - Unauthenticated Arbitrary Post Title Disclosure

Description

The plugin discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

Proof of Concept

Affects Plugins

Fixed in 12.6.0

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2025-06-20 (about 6 months ago)
Added
2025-06-20 (about 6 months ago)
Last Updated
2025-06-20 (about 6 months ago)

Other