← WordPress Vulnerabilities
WordPress security by component

Domain For Sale

Domain For Sale displays a domain-for-sale page or notice on a WordPress website.

Domain For Sale (domain-for-sale) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 14, 2026; the highest published CVSS base score is 8.8.

Plugin slug: domain-for-sale

CVE-2026-89023: Domain For Sale exposes offer records and deletion through unauthenticated REST requests

ThemeAtelier Domain For Sale before 3.5.2 lacks authorization checks on protected REST API endpoints. An unauthenticated caller can retrieve stored offers and dashboard statistics or supply a numeric offer identifier to delete an arbitrary offer. The exposed records include bidder contact information, offer details, messages, verification tokens, and business data. Those tokens and personal details create additional risk, although the export does not establish a specific follow-on account compromise. The authoritative export does not disclose the REST route names, HTTP methods, identifier parameter, or callback functions. Version 3.5.2 is the first fixed release identified by the record.

PublishedSep 14, 2026
Known safe version3.5.2
Published vulnerabilities for domain-for-sale
Safe version
Sep 14, 2026 CVE-2026-89023
Domain For Sale exposes offer records and deletion through unauthenticated REST requests
ThemeAtelier Domain For Sale before 3.5.2 lacks authorization checks on protected REST API endpoints. An unauthenticated caller can retrieve stored offers and dashboard statistics or supply a numeric offer identifier to delete an arbitrary offer. The exposed records include bidder contact information, offer details, messages, verification tokens, and business data. Those tokens and personal details create additional risk, although the export does not establish a specific follow-on account compromise. The authoritative export does not disclose the REST route names, HTTP methods, identifier parameter, or callback functions. Version 3.5.2 is the first fixed release identified by the record.
3.5.2
CVE8.8
NVDPending
Jun 06, 2025 CVE-2025-5239
Domain For Sale: Cross-site scripting
Domain For Sale is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending