PT-2025-17953 · WordPress · Order Delivery Date

Mike Gozdiskowski

·

Published

2025-04-26

·

Updated

2025-05-14

·

CVE-2025-2907

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Order Delivery Date WordPress plugin versions prior to 12.3.1
Description The issue concerns a lack of authorization and CSRF checks when importing settings in the Order Delivery Date WordPress plugin. This allows attackers to modify sensitive options, such as default user role to administrator and users can register, enabling them to register as an administrator of the site and gain complete control.
Recommendations For versions prior to 12.3.1, update to version 12.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings import functionality until a patch is applied. Additionally, monitor user registrations and role assignments closely to detect any potential malicious activity.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-2907

Affected Products

Order Delivery Date