ZeroHour

CVE-2026-89023

niche

Missing Authorization in ThemeAtelier Domain For Sale WordPress Plugin REST API

CVSS 4.0
8.8 high
EPSS
Published
()
Modified
AI analysis

The ThemeAtelier Domain For Sale plugin for WordPress before version 3.5.2 contains a missing authorization flaw (CWE-862) in its REST API endpoints, allowing unauthenticated attackers to reach protected resources without any credentials. The bug is triggered simply by sending crafted requests to the plugin's REST routes, which fail to verify user permissions. An attacker can retrieve stored offer records, delete arbitrary offers by numeric identifier, and pull dashboard statistics, exposing bidder contact information, offer details, private messages, verification tokens, and business data. Sites running any version prior to 3.5.2 with the plugin active are affected. No public proof-of-concept is known and the flaw does not appear in CISA's Known Exploited Vulnerabilities catalog, so there is no evidence of in-the-wild exploitation at this time.

What to do: Update Domain For Sale to version 3.5.2 or later immediately. Until patched, block unauthenticated access to the plugin's REST API namespace at the WAF or reverse proxy, and verify that REST permission callbacks are enforced. Afterward, audit offer records for unauthorized deletions or tampering, rotate any exposed verification tokens, and notify affected bidders if contact details or messages were disclosed.

Affected
ThemeAtelier Domain For Sale (WordPress plugin)before 3.5.2
Estimated exposure
nichelikely low thousands of sites at most (order of magnitude: ~1,000s) — No public active-install counts exist for this niche commercial plugin, which targets a narrow use case (domain-for-sale landing pages), so deployment is plausibly limited to a few thousand sites — clearly an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.