CVE-2023-52210
WordPress vulnerability analysis and mitigation

Overview

CVE-2023-52210 is a Broken Access Control vulnerability in the Product Delivery Date for WooCommerce – Lite WordPress plugin by Tyche Softwares. It affects all versions up to and including 2.7.0, and was reported by researcher Mika on December 10, 2023, with public disclosure by Patchstack on January 3, 2024. The CVE was formally published in the NVD on December 23, 2025. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-287 (Improper Authentication) and represents a broken access control issue — specifically, a missing authorization, authentication, or nonce token check in a plugin function (Patchstack). This flaw allows unauthenticated remote attackers to invoke functionality that should be restricted to privileged users, requiring no user interaction and no special configuration. The attack vector is network-accessible, with low complexity, making it straightforward to exploit at scale. No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation results in a limited availability impact (CVSS A:L), with no confidentiality or integrity impact according to the assigned vector. An unauthenticated attacker could trigger restricted plugin actions — such as manipulating delivery date settings or related WooCommerce order data — potentially disrupting store operations. The scope is limited to the affected WordPress installation and does not directly enable lateral movement or sensitive data exfiltration (Patchstack).

Mitigation and workarounds

The vulnerability is patched in version 2.7.1 of the Product Delivery Date for WooCommerce – Lite plugin. Site administrators should update to version 2.7.1 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, consult your hosting provider or web developer for assistance. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report for the period of January 1–7, 2024, providing broader community visibility. No significant vendor statements beyond Patchstack's disclosure or notable researcher commentary have been identified for this CVE.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15991HIGH8.8
  • file-manager
NoYesAug 06, 2026
CVE-2026-15459HIGH8.1
  • wpmudev-updates
NoYesAug 06, 2026
CVE-2026-7529HIGH7.5
  • wisecampaign
NoYesAug 05, 2026
CVE-2026-18325HIGH7.2
  • forminator
NoYesAug 06, 2026
CVE-2026-16636HIGH7.2
  • fluent-smtp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management