๐Ÿ” CVE Alert

CVE-2026-85009

UNKNOWN 0.0

RestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment Recovery

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverable state and to write notes to another customer's order.

Vendor unknown
Product restropress
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown restropress

Be the first to know when new unknown vulnerabilities affecting unknown restropress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / RestroPress
0 โ‰ค 3.4.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9731b0f3-76c2-4e0a-9630-9160299a37ee/

Credits

Usama Arshad WPScan