Payment Recovery Flaw in RestroPress Plugin Affects WordPress Users
CVE-2026-85009
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-85009?
The RestroPress plugin for WordPress through version 3.4.6 includes a significant flaw in its payment recovery process. This vulnerability allows unauthorized attackers to exploit the payment-recovery flow by submitting a request with a specific order identifier without verifying ownership. As a result, attackers can enumerate orders that can be recovered and potentially add notes to another user's order, compromising the integrity of customer data and undermining user trust.
Affected Version(s)
RestroPress 0 <= 3.4.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.