Domain For Sale
Domain For Sale displays a domain-for-sale page or notice on a WordPress website.
Domain For Sale (domain-for-sale) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 14, 2026; the highest published CVSS base score is 8.8.
domain-for-saleCVE-2026-89023: Domain For Sale exposes offer records and deletion through unauthenticated REST requests
ThemeAtelier Domain For Sale before 3.5.2 lacks authorization checks on protected REST API endpoints. An unauthenticated caller can retrieve stored offers and dashboard statistics or supply a numeric offer identifier to delete an arbitrary offer. The exposed records include bidder contact information, offer details, messages, verification tokens, and business data. Those tokens and personal details create additional risk, although the export does not establish a specific follow-on account compromise. The authoritative export does not disclose the REST route names, HTTP methods, identifier parameter, or callback functions. Version 3.5.2 is the first fixed release identified by the record.
| Safe version |
|
||
|---|---|---|---|
| Sep 14, 2026 |
CVE-2026-89023
Domain For Sale exposes offer records and deletion through unauthenticated REST requests
ThemeAtelier Domain For Sale before 3.5.2 lacks authorization checks on protected REST API endpoints. An unauthenticated caller can retrieve stored offers and dashboard statistics or supply a numeric offer identifier to delete an arbitrary offer. The exposed records include bidder contact information, offer details, messages, verification tokens, and business data. Those tokens and personal details create additional risk, although the export does not establish a specific follow-on account compromise. The authoritative export does not disclose the REST route names, HTTP methods, identifier parameter, or callback functions. Version 3.5.2 is the first fixed release identified by the record.
|
3.5.2 |
CVE8.8
NVDPending
|
| Jun 06, 2025 |
CVE-2025-5239
Domain For Sale: Cross-site scripting
Domain For Sale is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|