Description
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Sensitive Data and Deletion of Resources
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in the Domain For Sale plugin for WordPress arises from missing authorization checks in its REST API endpoints. Because the API does not verify that callers are authenticated or authorized, any internet-accessible user can retrieve stored offer records, delete offers by their numeric identifiers, and view dashboard statistics containing bidder contact information, offer details, messages, verification tokens, and business data. This flaw permits an attacker to both disclose confidential information and alter or remove legitimate data, undermining the confidentiality, integrity, and availability of the site’s business assets.

Affected Systems

WordPress installations running the ThemeAtelier Domain For Sale plugin with a version prior to 3.5.2 are impacted. The vulnerability is specific to the plugin’s REST API layer and therefore affects any site that has not upgraded the plugin beyond the vulnerable release.

Risk and Exploitability

The CVSS score of 8.8 assigns this flaw a high severity level. The EPSS score is not available, so current exploitation probability cannot be quantified, but the fact that the attack vector is an unauthenticated REST API request and no authentication is required implies that the risk of exploitation is potentially high. The flaw is not listed in the CISA KEV catalog, yet it remains a significant threat to any WordPress deployment using the vulnerable plugin. An attacker can take advantage of the exposed endpoints without needing credentials; the exploitable conditions are simply HTTP access to the site’s REST API.

Generated by OpenCVE AI on September 15, 2026 at 12:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Domain For Sale plugin to version 3.5.2 or later to obtain the authorization checks that have been added by the vendor
  • Restrict access to the WordPress REST API endpoints by limiting the requests to authenticated users via server or application‑level firewall rules
  • Monitor the site’s logs for anomalous API activity, such as repeated calls to offer deletion or retrieval endpoints, to detect possible exploitation attempts

Generated by OpenCVE AI on September 15, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Themeatelier
Themeatelier domain For Sale
Wordpress
Wordpress wordpress
Vendors & Products Themeatelier
Themeatelier domain For Sale
Wordpress
Wordpress wordpress

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.
Title ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Themeatelier Domain For Sale
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T20:05:24.150Z

Reserved: 2026-09-10T16:23:54.471Z

Link: CVE-2026-89023

cve-icon Vulnrichment

Updated: 2026-09-14T19:22:10.681Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T19:17:55.287

Modified: 2026-09-14T21:07:11.883

Link: CVE-2026-89023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:01:12Z

Weaknesses