Order Delivery Date Vulnerability

MEDIUM (5.4) No Patch (5 days)

Threat Intelligence

Low Risk
EPSS Score: 0.03% chance of exploitation (percentile: 7%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The Order Delivery Date plugin for WooCommerce is a popular add-on for e-commerce platforms. This vulnerability allows attackers to exploit incorrectly configured access control security levels, potentially leading to unauthorized access to sensitive data.

Am I affected?

You're affected if you use Missing Authorization vulnerability. Affected versions: 4.3.1 If you don't recognise this software, you're probably not affected.

Affected Products

DynamiApps / Order Delivery Date

How to fix

To fix this vulnerability, update to WooCommerce version 5.9.1 or later. Alternatively, apply immediate mitigations:
- Restrict network access to your WordPress installation (firewall it from the public internet)
- Audit plugin activation and deactivation logs for suspicious activity patterns
- Monitor for unauthorized plugin updates

References