Vulnerabilities / Retainful / WPSEC-2026-0549

Retainful <= 1.0.10 - Unauthenticated Missing Authorization to Connection Settings Update and Sensitive Information Exposure

Medium 6.5 CWE-862Fixed in 1.0.11
ID
WPSEC-2026-0549
Plugin
Email Marketing for WordPress and WooCommerce – Retainful (retainful)
Affected
all versions before 1.0.11
Remediation
Update to 1.0.11 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Retainful on WPSec AttackSurface
Fix released
Published

Description

The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized modification of data and exposure of sensitive information in all versions up to, and including, 1.0.10. The handshake/wordpress REST route was registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to overwrite the plugin's WordPress connection settings (API key, organization ID and app URL), replacing the site's Retainful connection, and to retrieve the site's general settings, including the administrator email address and the store address.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0