Vulnerabilities / Retainful / WPSEC-2026-0548

Retainful <= 1.0.10 - Authenticated (Subscriber+) Missing Authorization to Webhook Registration and Coupon Creation via REST API

High 7.1 CWE-862Fixed in 1.0.11
ID
WPSEC-2026-0548
Plugin
Email Marketing for WordPress and WooCommerce – Retainful (retainful)
Affected
from 1.0.4 before 1.0.11
Remediation
Update to 1.0.11 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Retainful on WPSec AttackSurface
Fix released
Published

Description

The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized access in versions 1.0.4 up to, and including, 1.0.10. The permission callback that protects the plugin's REST routes checks only that the supplied credentials are valid, with no capability check. This makes it possible for authenticated attackers with Subscriber-level access and above, using an application password for their own account, to register WooCommerce webhooks that send order and customer details for new orders to a URL they control, overwrite the plugin's Retainful connection settings, create arbitrary WooCommerce coupons, delete WooCommerce REST API keys and webhooks, and overwrite the stored popup configuration.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0