RestroPress vulnerability

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.

Published 18 Sep 2026Updated 18 Sep 20261 sources
CVSS 0.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.