RestroPress Online Food Ordering System WordPress plugin 3.0.0 to 3.1.9.2 contains an authentication bypass caused by exposure of user private tokens and API data via /wp-json/wp/v2/users endpoint, letting unauthenticated attackers forge JWT tokens and authenticate as other users including administrators, exploit requires no authentication.
id: CVE-2025-9209
info:
name: RestroPress 3.0.0-3.2.1 - Authentication Bypass
author: 0x_Akoko
...