Impact
The RestroPress WordPress plugin, in versions up to 3.4.6, contains a flaw in the payment‑recovery flow where ownership of an order is not verified before processing a request‑supplied order identifier. This flaw allows an unauthenticated attacker to enumerate which orders are in a recoverable state and to write arbitrarily notes to another customer’s order, thereby compromising the confidentiality and integrity of order information.
Affected Systems
Affected systems are installations of the RestroPress plugin for WordPress with a version of 3.4.6 or older.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability, and the EPSS score of less than 1% suggests a low probability of exploitation in the immediate term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is a web request to the payment‑recovery endpoint that accepts an order identifier without authentication, allowing any internet user to probe the endpoint and modify order notes.
OpenCVE Enrichment