Retainful <= 1.0.10 - Authenticated (Subscriber+) Missing Authorization to Webhook Registration and Coupon Creation via REST API
- ID
- WPSEC-2026-0548
- Plugin
- Email Marketing for WordPress and WooCommerce – Retainful (retainful)
- Affected
- from 1.0.4 before 1.0.11
- Remediation
- Update to 1.0.11 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Retainful on WPSec AttackSurface
- Fix released
- Published
Description
The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized access in versions 1.0.4 up to, and including, 1.0.10. The permission callback that protects the plugin's REST routes checks only that the supplied credentials are valid, with no capability check. This makes it possible for authenticated attackers with Subscriber-level access and above, using an application password for their own account, to register WooCommerce webhooks that send order and customer details for new orders to a URL they control, overwrite the plugin's Retainful connection settings, create arbitrary WooCommerce coupons, delete WooCommerce REST API keys and webhooks, and overwrite the stored popup configuration.
References
- https://wpsec.com/vuln/WPSEC-2026-0548/
- https://plugins.svn.wordpress.org/retainful/tags/1.0.11/
- https://wordpress.org/plugins/retainful/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS