CVE-2026-89023
nicheMissing Authorization in ThemeAtelier Domain For Sale WordPress Plugin REST API
The ThemeAtelier Domain For Sale plugin for WordPress before version 3.5.2 contains a missing authorization flaw (CWE-862) in its REST API endpoints, allowing unauthenticated attackers to reach protected resources without any credentials. The bug is triggered simply by sending crafted requests to the plugin's REST routes, which fail to verify user permissions. An attacker can retrieve stored offer records, delete arbitrary offers by numeric identifier, and pull dashboard statistics, exposing bidder contact information, offer details, private messages, verification tokens, and business data. Sites running any version prior to 3.5.2 with the plugin active are affected. No public proof-of-concept is known and the flaw does not appear in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.
What to do: Update Domain For Sale to version 3.5.2 or later immediately. Until patched, block unauthenticated access to the plugin's REST API namespace at the WAF or reverse proxy, and verify that REST permission callbacks are enforced. Afterward, audit offer records for unauthorized deletions or tampering, rotate any exposed verification tokens, and notify affected bidders if contact details or messages were disclosed.
| ThemeAtelier Domain For Sale (WordPress plugin) | before 3.5.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.