{
 "id": "WPSEC-2026-0548",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0548/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0548/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0548/index.md",
 "title": "Retainful <= 1.0.10 - Authenticated (Subscriber+) Missing Authorization to Webhook Registration and Coupon Creation via REST API",
 "description": "The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized access in versions 1.0.4 up to, and including, 1.0.10. The permission callback that protects the plugin's REST routes checks only that the supplied credentials are valid, with no capability check. This makes it possible for authenticated attackers with Subscriber-level access and above, using an application password for their own account, to register WooCommerce webhooks that send order and customer details for new orders to a URL they control, overwrite the plugin's Retainful connection settings, create arbitrary WooCommerce coupons, delete WooCommerce REST API keys and webhooks, and overwrite the stored popup configuration.",
 "plugin": {
  "slug": "retainful",
  "name": "Retainful",
  "full_name": "Email Marketing for WordPress and WooCommerce – Retainful",
  "wordpress_org": "https://wordpress.org/plugins/retainful/",
  "advisories_url": "https://wpsec.com/vuln/plugin/retainful/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/retainful"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.0.4",
    "from_inclusive": true,
    "to": "1.0.11",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.0.4 before 1.0.11"
  ]
 },
 "introduced_in": "1.0.4",
 "fixed_in": "1.0.11",
 "remediation": "Update to 1.0.11 or later.",
 "fix_released": "2026-10-05T08:06:34+00:00",
 "published": "2026-10-07T14:47:02+00:00",
 "updated": "2026-10-07T13:54:55.988412+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0548/",
  "https://plugins.svn.wordpress.org/retainful/tags/1.0.11/",
  "https://wordpress.org/plugins/retainful/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/retainful",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}