V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-2907
CVE
CriticalConfirmedExploit available

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it …

CVSS
9.8
Critical
EPSS
0.01
p66
Published
2025-01-01
Updated
2025-01-01
Description

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.

Tags · CWE
Pre-auth
CWE-352
CAPEC-62
CAPEC-111
CAPEC-462
CAPEC-467
Affected products
Order_delivery_date_pro_for_woocommerce < 12.3.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.013 · p66
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2025-2907
github-poc · https://github.com/Yucaerin/CVE-2025-2907
Enterprise
Affected products
ProductVendorStatus
order_delivery_date_pro_for_woocommerce*Tracked
Source databases
CVE