VYPR
Medium severity4.3NVD Advisory· Published Jul 11, 2025· Updated Jun 17, 2026

CVE-2025-2942

CVE-2025-2942

Description

The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.