CVE Database
/

CVE-2025-2942

Back to search

CVE-2025-2942

Published: Jul 11, 2025

Modified: Jul 15, 2025

PUBLISHED

Description

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

VendorProductVersions

Unknown

Order Delivery Date

affected
2.0 - < 12.6.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now