SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-89023

HIGH · CVSS 8.6 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The ThemeAtelier Domain For Sale plugin for WordPress prior to version 3.5.2 is vulnerable due to a missing authorization flaw in its REST API endpoints, enabling unauthenticated attackers to access and manipulate sensitive resources. This vulnerability allows attackers to retrieve stored offer records, delete offers, and access confidential dashboard statistics, potentially exposing bidder contact information and business data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data exposure and manipulation.

CVE
CVE-2026-89023
Severity
HIGH
CVSS
8.6
EPSS
0.23%
WordPress

Original NVD Description

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.