{
 "id": "WPSEC-2026-0549",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0549/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0549/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0549/index.md",
 "title": "Retainful <= 1.0.10 - Unauthenticated Missing Authorization to Connection Settings Update and Sensitive Information Exposure",
 "description": "The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized modification of data and exposure of sensitive information in all versions up to, and including, 1.0.10. The handshake/wordpress REST route was registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to overwrite the plugin's WordPress connection settings (API key, organization ID and app URL), replacing the site's Retainful connection, and to retrieve the site's general settings, including the administrator email address and the store address.",
 "plugin": {
  "slug": "retainful",
  "name": "Retainful",
  "full_name": "Email Marketing for WordPress and WooCommerce – Retainful",
  "wordpress_org": "https://wordpress.org/plugins/retainful/",
  "advisories_url": "https://wpsec.com/vuln/plugin/retainful/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/retainful"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.0.11",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.0.11"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.0.11",
 "remediation": "Update to 1.0.11 or later.",
 "fix_released": "2026-10-05T08:06:34+00:00",
 "published": "2026-10-07T14:47:02+00:00",
 "updated": "2026-10-07T13:54:55.988412+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0549/",
  "https://plugins.svn.wordpress.org/retainful/tags/1.0.11/",
  "https://wordpress.org/plugins/retainful/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/retainful",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}