Retainful <= 1.0.10 - Unauthenticated Missing Authorization to Connection Settings Update and Sensitive Information Exposure
- ID
- WPSEC-2026-0549
- Plugin
- Email Marketing for WordPress and WooCommerce – Retainful (retainful)
- Affected
- all versions before 1.0.11
- Remediation
- Update to 1.0.11 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Retainful on WPSec AttackSurface
- Fix released
- Published
Description
The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized modification of data and exposure of sensitive information in all versions up to, and including, 1.0.10. The handshake/wordpress REST route was registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to overwrite the plugin's WordPress connection settings (API key, organization ID and app URL), replacing the site's Retainful connection, and to retrieve the site's general settings, including the administrator email address and the store address.
References
- https://wpsec.com/vuln/WPSEC-2026-0549/
- https://plugins.svn.wordpress.org/retainful/tags/1.0.11/
- https://wordpress.org/plugins/retainful/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS