Impact
The vulnerability in the Domain For Sale plugin for WordPress arises from missing authorization checks in its REST API endpoints. Because the API does not verify that callers are authenticated or authorized, any internet-accessible user can retrieve stored offer records, delete offers by their numeric identifiers, and view dashboard statistics containing bidder contact information, offer details, messages, verification tokens, and business data. This flaw permits an attacker to both disclose confidential information and alter or remove legitimate data, undermining the confidentiality, integrity, and availability of the site’s business assets.
Affected Systems
WordPress installations running the ThemeAtelier Domain For Sale plugin with a version prior to 3.5.2 are impacted. The vulnerability is specific to the plugin’s REST API layer and therefore affects any site that has not upgraded the plugin beyond the vulnerable release.
Risk and Exploitability
The CVSS score of 8.8 assigns this flaw a high severity level. The EPSS score is not available, so current exploitation probability cannot be quantified, but the fact that the attack vector is an unauthenticated REST API request and no authentication is required implies that the risk of exploitation is potentially high. The flaw is not listed in the CISA KEV catalog, yet it remains a significant threat to any WordPress deployment using the vulnerable plugin. An attacker can take advantage of the exposed endpoints without needing credentials; the exploitable conditions are simply HTTP access to the site’s REST API.
OpenCVE Enrichment