---
id: CVE-2026-89023
title: >-
  ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a
  missing authorization vulnerability in its REST API endpoints that allows
  unauthenticated attackers to access and manipulate protected resources
summary: >-
  ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a
  missing authorization vulnerability in its REST API endpoints that allows
  unauthenticated attackers to access and manipulate protected resources.
  Attackers can ret…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'
cwe:
  - CWE-862
vendor: ThemeAtelier
product: Domain For Sale
affected:
  - domain_for_sale < 3.5.2
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:07:11.883'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89023'
references:
  - url: 'https://wordpress.org/plugins/domain-for-sale/#developers'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/themeatelier-domain-for-sale-missing-authorization-via-rest-api
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-14T19:22:09.612847Z'
ingestedAt: '2026-09-14T19:13:23.475Z'
epss: 0.00385
epssPercentile: 0.2977
---

## Overview

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can retrieve stored offer records, delete arbitrary offers by numeric identifier, and access dashboard statistics to disclose bidder contact information, offer details, messages, verification tokens, and business data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
