CVE-2025-2907 is a critical vulnerability affecting the Order Delivery Date WordPress plugin before version 12.3.1. It allows unauthenticated attackers to bypass authorization and CSRF checks during settings import, enabling them to modify critical WordPress options like default_user_role to administrator and users_can_register. This flaw has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability, leading to full site takeover. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.3.1CPE matchmatch criteria | cpe:2.3:a:tychesoftwares:order_delivery_date_pro_for_woocommerce:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.