plugin

Restropress Vulnerabilities

22 known security issues reported for the Restropress WordPress plugin. Most recent disclosed Dec 31, 2025.

1 critical 1 high 8 medium

Running Restropress on your site? Check whether your installed version is affected.

Scan your site free

RestroPress <= 3.2.7 - Missing Authorization

medium

The RestroPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.2.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
Dec 31, 2025

CVE-2025-62129 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] <= 3.2.4.2 (unfixed)

unknown

[en] Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through 3.2.4.2.

Affected:
up to 3.2.4.2
Fix:
No patched version reported
Disclosed:
Dec 31, 2025

CVE-2025-62129 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] <= 3.2.4.2 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Stored XSS.This issue affects RestroPress: from n/a through <= 3.2.4.2.

Affected:
up to 3.2.4.2
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-69017 on NVD →

RestroPress <= 3.2.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The RestroPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 3.2.8.6
Fixed in:
3.2.8.6.1
Disclosed:
Dec 27, 2025

CVE-2025-69017 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] <= 3.2.3.5 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.3.5.

Affected:
up to 3.2.3.5
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-66100 on NVD →

RestroPress <= 3.2.3.5 - Missing Authorization

medium

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.3.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized ac...

CVSS:
4.3
Affected:
up to 3.2.3.5
Fixed in:
3.2.3.6
Disclosed:
Nov 17, 2025

CVE-2025-66100 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] <= 3.0.0 (unfixed + closed)

unknown

[en] In the Linux kernel, the following vulnerability has been resolved: dax: Fix dax_mapping_release() use after free A CONFIG_DEBUG_KOBJECT_RELEASE test of removing a device-dax region provider (like modprobe -r dax_hmem) yields: kobject: 'mapping0' (ffff93eb460e8800): kobject_release, parent 0000000000000000 (de...

Affected:
up to 3.0.0
Fix:
No patched version reported
Disclosed:
Oct 4, 2025

CVE-2023-53613 on NVD →

RestroPress – Online Food Ordering System 3.0.0 - 3.2.1 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

critical

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Authentication Bypass in versions 3.0.0 to 3.2.1. This is due to the plugin exposing user private tokens and API data via the /wp-json/wp/v2/users REST API endpoint. This makes it possible for unauthenticated attackers to forge JWT toke...

CVSS:
9.8
Affected:
3.0.0 – 3.2.1
Fixed in:
3.2.2
Disclosed:
Oct 2, 2025

CVE-2025-9209 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] <= 3.1.8.4 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress allows Reflected XSS. This issue affects RestroPress: from n/a through 3.1.8.4.

Affected:
up to 3.1.8.4
Fix:
No patched version reported
Disclosed:
Apr 11, 2025

CVE-2025-32553 on NVD →

RestroPress <= 3.2.8.6 - Reflected Cross-Site Scripting

medium

The RestroPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.2.8.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 3.2.8.6
Fixed in:
3.2.8.6.1
Disclosed:
Apr 9, 2025

CVE-2025-32553 on NVD →

RestroPress <= 3.2.8 - Missing Authorization

medium

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized acti...

CVSS:
4.3
Affected:
up to 3.2.8
Fixed in:
3.2.8.1
Disclosed:
Apr 1, 2025

CVE-2025-31877 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] <= 3.1.8.4 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Magnigenie RestroPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RestroPress: from n/a through 3.1.8.4.

Affected:
up to 3.1.8.4
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31877 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] < 3.1.2.2 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress: from n/a through 3.1.2.1.

Affected:
up to 3.1.2.2
Fixed in:
3.1.2.2
Disclosed:
Jun 8, 2024

CVE-2024-35719 on NVD →

RestroPress – Online Food Ordering System <= 3.1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The RestroPress – Online Food Ordering System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
6.4
Affected:
up to 3.1.2.1
Fixed in:
3.1.2.2
Disclosed:
Jun 6, 2024

CVE-2024-35719 on NVD →

RestroPress &#8211; Online Food Ordering System [restropress] < 3.1.2.1 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a through 3.1.2.

Affected:
up to 3.1.2.1
Fixed in:
3.1.2.1
Disclosed:
Apr 15, 2024

CVE-2024-32449 on NVD →

RestroPress <= 3.1.2 - Cross-Site Request Forgery via rpress_orders_list_table_process_bulk_actions

medium

The RestroPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.2. This is due to missing or incorrect nonce validation on the rpress_orders_list_table_process_bulk_actions() function. This makes it possible for unauthenticated attackers to perform bulk actions via...

CVSS:
4.3
Affected:
up to 3.1.2
Fixed in:
3.1.2.1
Disclosed:
Apr 12, 2024

CVE-2024-32449 on NVD →

RestroPress <= 2.8.2 - Cross-Site Request Forgery to Cart Manipulation

high

The RestroPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing nonce validation on various AJAX actions. This makes it possible for unauthenticated attackers to modify the contents of other users' carts via a forged request granted they c...

CVSS:
8.8
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Jul 19, 2021

RestroPress <= 2.8.3 - Missing Authorization

medium

The RestroPress plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 2.8.3. This is due to improper nonce and capability checks in several of the AJAX calls. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to access restricted o...

CVSS:
5.4
Affected:
up to 2.8.3
Fixed in:
2.8.3.1
Disclosed:
Jul 19, 2021

RestroPress &#8211; Online Food Ordering System [restropress] < 2.8.3 (closed)

unknown

The RestroPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing nonce validation on various AJAX actions. This makes it possible for unauthenticated attackers to modify the contents of other users' carts via a forged request granted they c...

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Jul 19, 2021

RestroPress &#8211; Online Food Ordering System [restropress] < 2.8.3.1 (closed)

unknown

The RestroPress plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 2.8.3. This is due to improper nonce and capability checks in several of the AJAX calls. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to access restricted o...

Affected:
up to 2.8.3.1
Fixed in:
2.8.3.1
Disclosed:
Jul 19, 2021

RestroPress &#8211; Online Food Ordering System [restropress] < 2.8.3 (closed)

unknown

The plugin does not properly check for CSRF in some of its AJAX calls, allowing attackers to make users do unwanted actions, such as add arbitrary products to their cart, or empty it completely

Affected:
up to 2.8.3
Fixed in:
2.8.3

RestroPress &#8211; Online Food Ordering System [restropress] < 2.8.3.1 (closed)

unknown

The plugin did not check for CSRF as well as capability in some of its AJAX calls which should only be accessible by admin. As a result, any authenticated user can change arbitrary order status, as well as access arbitrary order details (including PII such as phone number and address)

Affected:
up to 2.8.3.1
Fixed in:
2.8.3.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database