Order Delivery Date WordPress Plugin Sensitive Data Disclosure Vulnerability

Vulnerability

A vulnerability in the Order Delivery Date WordPress plugin, affecting versions prior to 12.6.0, allows for the unauthorized disclosure of post titles, including those from draft and private posts. This information leak occurs through an unauthenticated AJAX action, enabling attackers to retrieve sensitive data.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive post titles, including those from private and draft posts.

Reproduction

To reproduce this vulnerability, send a request to 'wp-admin/admin-ajax.php' with the 'action' parameter set to 'orddd_order_calendar_content', along with a valid order ID and an arbitrary post ID. This can be done without authentication, allowing for the retrieval of post titles through the AJAX response.

Remediation

Users are advised to update the Order Delivery Date WordPress plugin to version 12.6.0 or later.

Added: Jul 11, 2025, 6:25 AM
Updated: Jul 11, 2025, 6:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
7.7
relevance
0.2
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.