PT-2025-40490 · WordPress · Restropress – Online Food Ordering System
Kenneth Dunn
·
Published
2025-10-03
·
Updated
2026-04-23
·
CVE-2025-9209
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RestroPress – Online Food Ordering System plugin for WordPress versions 3.0.0 through 3.1.9.2
Description
The RestroPress plugin for WordPress is affected by an authentication bypass issue. The plugin exposes user private tokens and API data through the
/wp-json/wp/v2/users API endpoint. This allows unauthenticated attackers to forge JSON Web Tokens (JWT) for other users, including administrators, and authenticate as them. The user private tokens are exposed, enabling JWT forgery.Recommendations
Update to a version later than 3.1.9.2.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Restropress – Online Food Ordering System