Executive brief
ThemeAtelier Domain For Sale is a WordPress plugin that allows domain investors to create landing pages, accept buyer offers, and manage domain sales directly from WordPress. The plugin's REST API endpoints lack proper authorization checks, allowing unauthenticated attackers to read sensitive business data (buyer contact information, offer amounts, messages, verification tokens) and delete offers, potentially disrupting sales operations and exposing confidential negotiations.
Technical details
The vulnerability is a missing authorization flaw (CWE-862) in the plugin's REST API endpoints. Attackers can make unauthenticated network requests to REST endpoints that should be restricted to authorized users or administrators. The attack requires no user interaction or authentication. Successful exploitation allows retrieval of stored offer records including bidder contact information, offer details, messages, and verification tokens; deletion of arbitrary offers by numeric identifier; and access to dashboard statistics containing business data. The vulnerability affects versions before 3.5.2; a patch is available in version 3.5.2 and later.
Affected products
- ThemeAtelier Domain For Sale before 3.5.2
Timeline
- 2026-09-14: disclosed: Vulnerability publicly disclosed
- 2026-09-14: patched: Fix available in version 3.5.2