External risk intelligence

RestroPress Authentication Bypass via User Data Exposure

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-9209

The vulnerability affects a WordPress plugin designed for online food ordering. Such plugins are typically deployed on public-facing websites to enable customer interactions, making the REST API endpoints used by the plugin inherently accessible from the public internet in standard operational configurations.

Information Disclosure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability affects an online food ordering plugin for WordPress. It allows unauthenticated attackers to bypass security controls, potentially impersonate any user, including administrators, by exploiting how user data is exposed through the system's API. The main concern is confirming whether this specific technology is in use and, if so, assessing the potential exposure.

  • Bypasses security, allowing unauthorized access.
  • Affects online ordering systems, a common public-facing tool.
  • Confirm usage and assess exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can access the user endpoint of the RestroPress plugin to obtain private user tokens and API data. This exposure allows them to forge JWT tokens for any user, including administrators, granting them the ability to impersonate legitimate users and gain unauthorized access.

  • No authentication required.
  • Accesses user data via API.
  • Enables administrator impersonation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to bypass authentication and impersonate any user, including administrators, by forging JWT tokens. This is possible because the plugin exposes user private tokens and API data through a REST API endpoint.

  • User accounts and administrative access.
  • Exploiting exposed API data via REST endpoint.
  • Unauthorized access and system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in an online food ordering plugin for WordPress requires immediate attention from teams managing WordPress deployments and associated security. The primary step is to locate all instances of the affected plugin, assess their exposure and business criticality, and identify the accountable owner before planning remediation.

  • WordPress and application owners should lead.
  • Verify plugin reachability and critical assets.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the RestroPress plugin used for?

RestroPress is a specialized WordPress plugin designed to turn a standard website into an online food ordering and management platform. It handles essential tasks like menu display, cart functionality, and order processing for restaurants. Because it is a business-facing tool, it is typically installed on web servers where customers can access it directly to place food orders.

How does CVE-2025-9209 allow authentication bypass?

This vulnerability falls under the CWE-200 weakness class, which involves the exposure of sensitive information. In this specific case, the plugin accidentally reveals private user tokens and API data through a public REST API endpoint. An attacker can collect this leaked data to forge valid login tokens, tricking the system into believing they are a legitimate, logged-in user—such as an administrator—without ever providing a password.

What triggers the vulnerability in CVE-2025-9209?

The issue is triggered when an attacker sends requests to the specific /wp-json/wp/v2/users REST API endpoint that the plugin leaves exposed. Importantly, the vulnerability does not require the attacker to have any prior access or account permissions; it is accessible to anyone on the network. Using the plugin for legitimate, authenticated site management does not inherently cause this bug, but leaving the vulnerable version active allows the exposure to occur automatically.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin, your site is at higher risk. Halo Surface Signal identifies this as a 'Likely' issue because online food ordering systems are almost always intentionally connected to the public internet to function. Since the vulnerable API endpoint is exposed to that same internet-facing path, an attacker does not need to bypass a firewall or have internal network access to exploit the flaw.

Do I need to take action if I use RestroPress?

Yes. First, you should identify all WordPress installations in your environment where this plugin is currently active. Once located, verify who manages those sites and assess the business impact of a potential compromise. Your goal is to coordinate with the site owners to remove the exposure, which may involve disabling the plugin, restricting access to the affected API, or coordinating with the vendor for a security update.

References