PT-2025-40490 · WordPress · Restropress – Online Food Ordering System

Kenneth Dunn

·

Published

2025-10-03

·

Updated

2026-04-23

·

CVE-2025-9209

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RestroPress – Online Food Ordering System plugin for WordPress versions 3.0.0 through 3.1.9.2
Description The RestroPress plugin for WordPress is affected by an authentication bypass issue. The plugin exposes user private tokens and API data through the /wp-json/wp/v2/users API endpoint. This allows unauthenticated attackers to forge JSON Web Tokens (JWT) for other users, including administrators, and authenticate as them. The user private tokens are exposed, enabling JWT forgery.
Recommendations Update to a version later than 3.1.9.2.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9209

Affected Products

Restropress – Online Food Ordering System