Description
Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.3.1.
Published: 2025-12-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported flaw is a missing authorization issue in the Order Delivery Date for WooCommerce plugin that allows attackers to exploit incorrectly configured access control security levels. This weakness can enable an attacker to read and manipulate order delivery dates and potentially other order details that should be protected by the platform’s role restrictions, thereby compromising the integrity of the order processing workflow.

Affected Systems

The vulnerability impacts the tychesoftwares Order Delivery Date for WooCommerce plugin versions from the initial release through 4.3.1. Sites running WordPress installations with any of these plugin versions are affected.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, with an EPSS score of less than 1% suggesting the vulnerability is not widely targeted at present and it is not listed in the CISA KEV catalog. The likely attack vector is remote, via the publicly exposed web interface of the plugin, and an adversary could exploit the broken access control by submitting crafted requests to endpoints that normally require higher‑level permissions. The low EPSS and absence from KEV suggest current exploitation risk is modest, but the potential for unauthorized modification of order data warrants prompt action.

Generated by OpenCVE AI on April 29, 2026 at 19:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Order Delivery Date for WooCommerce release, version 4.3.2 or newer.
  • Restrict administrative access to the plugin’s configuration and order‑date editing features by assigning only trusted WordPress roles.
  • Implement an additional layer of role‑based access checks in the plugin’s code, ensuring that any endpoint capable of changing order details verifies the requester’s permissions before proceeding.

Generated by OpenCVE AI on April 29, 2026 at 19:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Tychesoftwares
Tychesoftwares order Delivery Date For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Tychesoftwares
Tychesoftwares order Delivery Date For Woocommerce
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.3.1.
Title WordPress Order Delivery Date for WooCommerce plugin <= 4.3.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Tychesoftwares Order Delivery Date For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:08.763Z

Reserved: 2025-10-24T14:25:44.112Z

Link: CVE-2025-63024

cve-icon Vulnrichment

Updated: 2025-12-10T17:17:03.105Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:07.283

Modified: 2026-04-27T19:16:18.600

Link: CVE-2025-63024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:30:18Z

Weaknesses