← Zuruck zu CVEs
CVE-2025-2907
CRITICAL9.8
Beschreibung
The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht4/26/2025
Zuletzt geandert5/14/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
tychesoftwares:order_delivery_date_pro_for_woocommerce
Schwachen (CWE)
CWE-352
Referenzen
https://wpscan.com/vulnerability/2e513930-ec01-4dc6-8991-645c5267e14c/(contact@wpscan.com)
https://wpscan.com/vulnerability/2e513930-ec01-4dc6-8991-645c5267e14c/(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.