S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Apr 23, 2026

CVE-2025-9209 Scanner

CVE-2025-9209 Scanner - Authentication Bypass vulnerability in RestroPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-9209
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
RestroPress – Online Food Ordering Systemby magnigenie
3.0.0
Updated Aug 5, 2026View on NVD →
Detail

RestroPress is a popular online food ordering system used by WordPress websites, primarily by restaurants and food businesses to facilitate online order taking. It is favored for its user-friendly interface and efficient order management process. Many small and medium-sized businesses prefer using this plugin due to its seamless integration with WordPress and various payment gateways. Users can place orders through an easy-to-use menu interface, making it convenient for customers and staff alike. Installed as a WordPress plugin, RestroPress is an extension enhancing the existing capabilities of WordPress-powered sites. It plays a vital role in a business's online presence, impacting sales and customer engagement.

The authentication bypass vulnerability discovered in RestroPress allows unauthorized attackers to gain access to user accounts. By exploiting this issue, malicious users can forge JWT tokens, posing as valid users. This potentially grants them access to sensitive user information and control over accounts, including administrator accounts. The vulnerability is significantly relevant because it does not require prior authentication, making it easier for attackers to exploit. This security loophole affects versions from 3.0.0 to 3.2.1, where exposures occur due to improper handling of user tokens and API data. Special focus is required to handle this issue to prevent misuse and data breaches.

The technical details of the authentication bypass exploit revolve around the exposure of user tokens via the /wp-json/wp/v2/users endpoint. This improper token handling allows attackers to create malicious JWT tokens. Tools checking the endpoint can expose how the vulnerability occurs when no proper authentication measures secure token generation and validation processes. In practice, attackers can exploit this by sending requests that result in them acquiring unauthorized tokens used to access other users' data. The endpoint essentially leaks API data creating a dangerous path for malicious intrusions. Version checks reaffirm its impact range and highlight where fixes should be proactively applied.

If exploited, this vulnerability can have severe repercussions, including unauthorized access to sensitive data and complete account takeovers. Attackers can use the forged JWT tokens to authenticate as users, enabling potential breaches into user accounts, including those with administrative privileges. This could lead to data sabotage, site defacement, unauthorized transactions, and full-scale identity theft. Further issues could include data integrity challenges, loss of customer trust, and potential legal consequences for businesses. Consequently, protecting systems against this vulnerability should be a high-priority concern for affected users.

REFERENCES

Solution Advice
  • Update RestroPress plugin to a version beyond 3.1.9.2 to mitigate the vulnerability.
  • Implement additional security layers such as multi-factor authentication (MFA) to enhance login security.
  • Regularly monitor and audit WordPress installations for exposed endpoints and potential security misconfigurations.
  • Conduct routine security assessments to identify and fix unauthorized access paths.
  • Regularly backup sensitive data and configurations for rapid recovery in case of unauthorized data access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.