S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated May 2, 2025

CVE-2025-2907 Scanner

CVE-2025-2907 Scanner - Unauthenticated Admin Account Creation vulnerability in Order Delivery Date Pro for WooCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2907
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks proper checks to only update options relevant to the Order Delivery Date WordPress plugin before 12.3.1. This leads to attackers being able to modify the default_user_role to administrator and users_can_register, allowing them to register as an administrator of the site for complete site takeover.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Order Delivery Date
AFFECTED< 12.3.1SAFE ✓≥ 12.3.1
Updated Aug 22, 2026View on NVD →
Detail

The Order Delivery Date Pro for WooCommerce is a WordPress plugin used primarily by e-commerce businesses to enhance their order management functionality. It allows online stores to offer customers options for selecting delivery dates for their orders, improving customer satisfaction by providing convenient delivery timing. The plugin is widely deployed across various sectors, including retail, food and beverage, and more. It's an essential tool for businesses that rely on timely product deliveries. Moreover, it is applicable across WooCommerce platforms where managing delivery schedules efficiently is a priority. It significantly contributes to a seamless shopping experience, making it popular among online retail businesses.

The Unauthenticated Admin Account Creation vulnerability is a critical security flaw in Order Delivery Date Pro for WooCommerce versions before 12.3.1. This vulnerability arises due to insufficient authorization and CSRF (Cross-Site Request Forgery) checks, allowing attackers to import settings without proper validation. This flaw can be exploited to change the default user role to "administrator," thereby giving unauthorized users the ability to register as administrators. The vulnerability essentially opens a backdoor for complete site takeover by malicious users. Given its severity, this vulnerability requires immediate attention to prevent unauthorized and potentially harmful site access.

The vulnerability is technically characterized by inadequate checks in the import settings functionality of the plugin. Attackers can exploit this by sending specially crafted requests to the affected endpoint, typically within the /wp-admin/admin-ajax.php pathway. These requests, if unchecked, modify essential WordPress site configuration options, specifically the 'default_user_role', which can be set to 'administrator'. Moreover, the 'users_can_register' option can be toggled, enabling attackers to register as new users with administrative privileges. The vulnerability is a result of the lack of stringent security checks on the server-side script handling the import file.

When exploited, this vulnerability potentially allows complete administrative control over an affected WordPress site. Malicious entities could add, modify, or delete content, install plugins and themes, and potentially inject malware to further compromise site security. Such exploitation can lead to substantial data breaches, unauthorized access to sensitive customer information, and a significant threat to business operations. The website's integrity is compromised, and recovering from such breaches can be resource-intensive both in terms of time and cost.

REFERENCES

Solution Advice
  • Update the Order Delivery Date Pro for WooCommerce plugin to version 12.3.1 or later.
  • Implement robust authorization checks in your WordPress site to prevent unauthorized account creation.
  • Regularly audit and review user privileges and roles assigned within your WordPress environment.
  • Enable security plugins that can detect and prevent unauthorized access attempts.
  • Maintain a comprehensive logging mechanism to monitor and respond to suspicious activities promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.