Junglewise Threat Intelligence

CVE-2026-42386: Tyche Softwares Order Delivery Date for WooCommerce SQL injection

CVE-2026-42386 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Vendors: Tyche Softwares.

Executive brief

A security vulnerability exists in the Order Delivery Date for WooCommerce plugin, which is used by online stores to manage customer delivery schedules. An unauthorized attacker can exploit this flaw to access the website's database without needing a password. This could lead to the theft of sensitive customer information, order details, or other private store data.

Technical details

The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). The vulnerability exists in versions up to and including 4.5.1. A remote, unauthenticated attacker can exploit this by sending specially crafted web requests to the server, allowing them to bypass authentication and directly interact with the underlying database. This can result in unauthorized data extraction or modification. The issue is resolved in version 4.5.2.

Affected products

  • Tyche Softwares Order Delivery Date for WooCommerce <= 4.5.1

Timeline

  • 2026-01-14: other: Reported by researcher daroo
  • 2026-04-27: advisory: Patchstack published advisory
  • 2026-06-15: disclosed: NVD published CVE record
  • 2026-04-27: patched: Version 4.5.2 released

References