PT-2025-17953 · WordPress · Order Delivery Date
Mike Gozdiskowski
·
Published
2025-04-26
·
Updated
2025-05-14
·
CVE-2025-2907
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Order Delivery Date WordPress plugin versions prior to 12.3.1
Description
The issue concerns a lack of authorization and CSRF checks when importing settings in the Order Delivery Date WordPress plugin. This allows attackers to modify sensitive options, such as
default user role to administrator and users can register, enabling them to register as an administrator of the site and gain complete control.Recommendations
For versions prior to 12.3.1, update to version 12.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings import functionality until a patch is applied. Additionally, monitor user registrations and role assignments closely to detect any potential malicious activity.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Order Delivery Date