Description
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Published: 2026-08-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Order Delivery Date for WooCommerce plugin for WordPress and permits a user with a shop manager role to elevate privileges within the WordPress site. This escalated access allows the attacker to gain the full capabilities of an administrator, compromising confidentiality, integrity, and availability of site content and settings.

Affected Systems

All installations of the Order Delivery Date for WooCommerce plugin at or below version 4.6.0 are affected. The plugin is provided by Tyche Softwares under the vendor name 'tychesoftwares:Order Delivery Date for WooCommerce.'

Risk and Exploitability

The CVSS score for this flaw is 7.2, indicating a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits yet. The most probable attack vector is local: a user with shop manager permissions can exploit the flaw directly through the plugin interface or by submitting crafted requests to the site. Once exploited, the attacker can restructure user roles and compromise site management functions.

Generated by OpenCVE AI on August 6, 2026 at 16:14 UTC.

Remediation

Vendor Solution

Update the WordPress Order Delivery Date for WooCommerce Plugin to the latest available version (at least 4.6.1).


OpenCVE Recommended Actions

  • Update the Order Delivery Date for WooCommerce plugin to version 4.6.1 or later.
  • Temporarily deactivate or remove the plugin the update is successfully applied.
  • Restrict shop manager accounts by limiting role capabilities or removing shop manager privileges if not required.

Generated by OpenCVE AI on August 6, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Tychesoftwares
Tychesoftwares order Delivery Date For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Tychesoftwares
Tychesoftwares order Delivery Date For Woocommerce
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Title WordPress Order Delivery Date for WooCommerce plugin <= 4.6.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Tychesoftwares Order Delivery Date For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T15:22:19.456Z

Reserved: 2026-07-22T08:54:23.962Z

Link: CVE-2026-65559

cve-icon Vulnrichment

Updated: 2026-08-06T15:22:16.101Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:15:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment