Authentication Bypass Vulnerability in RestroPress Plugin for WordPress
CVE-2025-9209

9.8CRITICAL

What is CVE-2025-9209?

The RestroPress plugin for WordPress is susceptible to an authentication bypass issue due to the improper exposure of user private tokens and API data through the /wp-json/wp/v2/users REST API endpoint. This vulnerability allows unauthenticated individuals to forge JWT tokens, enabling them to impersonate other users, including administrative accounts. It is crucial for users of the affected versions to implement patches or upgrades to mitigate the risks associated with this security flaw.

Affected Version(s)

RestroPress – Online Food Ordering System 3.0.0 <= 3.1.9.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.
CVE-2025-9209 : Authentication Bypass Vulnerability in RestroPress Plugin for WordPress