Order Delivery Date
cpe:2.3:a:tychesoftwares:order_delivery_date_for_woocommerce:*:*:*:*:wordpress:*:*
- < 12.3.1
A vulnerability exists in the Order Delivery Date WordPress plugin, specifically in versions prior to 12.3.1. The issue arises because the plugin lacks proper authorization and Cross-Site Request Forgery (CSRF) protections when importing settings. Additionally, it fails to restrict option updates to those relevant to the plugin. As a result, attackers can manipulate certain user role settings, such as changing the default user role to administrator and enabling user registration as an administrator, potentially leading to a complete takeover of the site.
Exploitation of this vulnerability allows for unauthorized users to gain administrative access to the WordPress site, effectively taking over the site.
Users are advised to update the Order Delivery Date WordPress plugin to version 12.3.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.