CyberRota Analysis
AI-GeneratedThe ThemeAtelier Domain For Sale plugin for WordPress prior to version 3.5.2 is vulnerable due to a missing authorization flaw in its REST API endpoints, enabling unauthenticated attackers to access and manipulate sensitive resources. This vulnerability allows attackers to retrieve stored offer records, delete offers, and access confidential dashboard statistics, potentially exposing bidder contact information and business data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized data exposure and manipulation.
Original NVD Description
ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.