# Retainful <= 1.0.10 - Unauthenticated Missing Authorization to Connection Settings Update and Sensitive Information Exposure

- **ID:** WPSEC-2026-0549
- **Plugin:** Email Marketing for WordPress and WooCommerce – Retainful (`retainful`), https://wordpress.org/plugins/retainful/
- **Affected versions:** all versions before 1.0.11
- **Fixed in:** 1.0.11 (Update to 1.0.11 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/retainful
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0549/

## Description

The Email Marketing for WordPress and WooCommerce - Retainful plugin for WordPress is vulnerable to unauthorized modification of data and exposure of sensitive information in all versions up to, and including, 1.0.10. The handshake/wordpress REST route was registered with a permission callback that always allows access. This makes it possible for unauthenticated attackers to overwrite the plugin's WordPress connection settings (API key, organization ID and app URL), replacing the site's Retainful connection, and to retrieve the site's general settings, including the administrator email address and the store address.

## References

- https://wpsec.com/vuln/WPSEC-2026-0549/
- https://plugins.svn.wordpress.org/retainful/tags/1.0.11/
- https://wordpress.org/plugins/retainful/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0549/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
