← Volver a CVEs
CVE-2025-2907
CRITICAL9.8
Descripcion
The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado4/26/2025
Ultima modificacion5/14/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
tychesoftwares:order_delivery_date_pro_for_woocommerce
Debilidades (CWE)
CWE-352
Referencias
https://wpscan.com/vulnerability/2e513930-ec01-4dc6-8991-645c5267e14c/(contact@wpscan.com)
https://wpscan.com/vulnerability/2e513930-ec01-4dc6-8991-645c5267e14c/(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.