CVE-2026-85009

CVE-2026-85009 published: The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write...

View full NVD advisory → ← Back to CVE watch