CVE-2026-85009
RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.
| Vendor | unknown |
| Product | restropress |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown restropress
Be the first to know when new unknown vulnerabilities affecting unknown restropress are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / RestroPress
0 โค 3.4.6
References
Credits
Usama Arshad WPScan