Authentication Bypass Vulnerability in RestroPress Plugin for WordPress
CVE-2025-9209
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2025
What is CVE-2025-9209?
The RestroPress plugin for WordPress is susceptible to an authentication bypass issue due to the improper exposure of user private tokens and API data through the /wp-json/wp/v2/users REST API endpoint. This vulnerability allows unauthenticated individuals to forge JWT tokens, enabling them to impersonate other users, including administrative accounts. It is crucial for users of the affected versions to implement patches or upgrades to mitigate the risks associated with this security flaw.
Affected Version(s)
RestroPress – Online Food Ordering System 3.0.0 <= 3.1.9.2