The Order Delivery Date WordPress plugin before 12.6.0 discloses arbitrary post title (such as from draft and private posts) via an unauthenticated AJAX action, allowing attackers to retrieve such information
| Software | From | Fixed in |
|---|---|---|
| tychesoftwares / order_delivery_date_for_woocommerce | - | 12.6.0 |