Description
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized order data exposure and modification
Action: Patch promptly
AI Analysis

Impact

The RestroPress WordPress plugin, in versions up to 3.4.6, contains a flaw in the payment‑recovery flow where ownership of an order is not verified before processing a request‑supplied order identifier. This flaw allows an unauthenticated attacker to enumerate which orders are in a recoverable state and to write arbitrarily notes to another customer’s order, thereby compromising the confidentiality and integrity of order information.

Affected Systems

Affected systems are installations of the RestroPress plugin for WordPress with a version of 3.4.6 or older.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability, and the EPSS score of less than 1% suggests a low probability of exploitation in the immediate term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is a web request to the payment‑recovery endpoint that accepts an order identifier without authentication, allowing any internet user to probe the endpoint and modify order notes.

Generated by OpenCVE AI on September 19, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a RestroPress version newer than 3.4.6 where the ownership check is applied.
  • If an upgrade is not immediately possible, block unauthenticated requests to the payment‑recovery URL using a firewall or a web application firewall that enforces authentication.
  • As a temporary workaround, disable or restrict access to the payment recovery functionality through plugin settings or custom code that rejects unauthenticated requests.
  • Monitor web server logs for suspicious activity targeting the payment‑recovery endpoint and investigate any anomalous requests.

Generated by OpenCVE AI on September 19, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions restropress
Vendors & Products Wordpress-extensions
Wordpress-extensions restropress

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
Title RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery
References

Subscriptions

Wordpress-extensions Restropress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:12:10.048Z

Reserved: 2026-09-02T18:44:48.259Z

Link: CVE-2026-85009

cve-icon Vulnrichment

Updated: 2026-09-18T11:04:32.308Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:39.760

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-85009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key