Order Delivery Date
- < 12.6.0
A vulnerability in the Order Delivery Date WordPress plugin, affecting versions prior to 12.6.0, allows for the unauthorized disclosure of post titles, including those from draft and private posts. This information leak occurs through an unauthenticated AJAX action, enabling attackers to retrieve sensitive data.
Exploitation of this vulnerability leads to unauthorized access to sensitive post titles, including those from private and draft posts.
To reproduce this vulnerability, send a request to 'wp-admin/admin-ajax.php' with the 'action' parameter set to 'orddd_order_calendar_content', along with a valid order ID and an arbitrary post ID. This can be done without authentication, allowing for the retrieval of post titles through the AJAX response.
Users are advised to update the Order Delivery Date WordPress plugin to version 12.6.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.