CVE-2026-89023
ThemeAtelier · Domain For Sale
The ThemeAtelier Domain For Sale plugin for WordPress contains a missing authorization flaw in its REST API, allowing unauthenticated attackers to access and manipulate sensitive business data.
Executive summary
An unauthenticated authorization bypass in the ThemeAtelier Domain For Sale WordPress plugin exposes sensitive bidder and business data to unauthorized access and manipulation.
Vulnerability
This vulnerability is a missing authorization flaw (CWE-862) within the plugin REST API endpoints. It allows unauthenticated attackers to bypass security checks to retrieve, modify, or delete sensitive records and dashboard statistics.
Business impact
The vulnerability poses a severe risk to data confidentiality and integrity, as attackers can exfiltrate bidder contact information, private messages, and verification tokens. Given the CVSS score of 8.6, this flaw represents a high risk to business operations, potentially leading to regulatory non-compliance, reputational damage, and the compromise of proprietary business transactions.
Remediation
Immediate Action: Update the ThemeAtelier Domain For Sale plugin to version 3.5.2 or later immediately to resolve the missing authorization flaw.
Proactive Monitoring: Review access logs for unusual REST API requests targeting plugin endpoints and monitor the dashboard for unauthorized changes to offer records or business statistics.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access to the affected REST API endpoints until the update can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The high CVSS score reflects the significant risk posed by this unauthenticated access vulnerability. IT administrators should prioritize the update to version 3.5.2 as the primary method of mitigation. If the plugin is not actively required for business operations, it should be deactivated or removed to eliminate the attack surface entirely.
More ThemeAtelier CVEs
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
Originally found and disclosed by Labda, per the CVE Program record.
- WordPress Changelog Release notes
- Third-party advisory