Known CVE
RestroPress 3.0.0-3.2.1 - Authentication Bypass
RestroPress Online Food Ordering System WordPress plugin 3.0.0 to 3.1.9.2 contains an authentication bypass caused by exposure of user private tokens and API data via /wp-json/wp/v2/users endpoint, letting unauthenticated attackers forge JWT tokens and authenticate as other users including administrators, exploit requires no authentication.
CVE-2025-9209
Critical2025CVSS 9.8CWE-287
cve2025 · wordpress · wp · wp-plugin · restropress · auth-bypass
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website