Filtered by vendor Magnigenie Subscriptions
Filtered by product Restropress Subscriptions
Total 5 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-9209 2 Magnigenie, Wordpress 2 Restropress, Wordpress 2025-10-06 9.8 Critical
The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.1.9.2. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT tokens for other users, including administrators, and authenticate as them.
CVE-2025-32553 2 Magnigenie, Wordpress 2 Restropress, Wordpress 2025-07-12 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress allows Reflected XSS. This issue affects RestroPress: from n/a through 3.1.8.4.
CVE-2025-31877 2 Magnigenie, Wordpress 2 Restropress, Wordpress 2025-07-12 4.3 Medium
Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RestroPress: from n/a through 3.1.8.4.
CVE-2024-35719 1 Magnigenie 1 Restropress 2024-11-21 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress: from n/a through 3.1.2.1.
CVE-2024-32449 1 Magnigenie 1 Restropress 2024-11-21 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a through 3.1.2.