WordPress security by component
CAFEHAUS API
Plugin description
CAFEHAUS API is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
cafe-apiLatest vulnerability
CVE-2026-12981: CAFEHAUS API exposes an unauthenticated password-change route
CAFEHAUS API through 1.0.0 registers POST /wp-json/cafe/v1/user/password/update without a permission_callback. The public handler accepts attacker-controlled userId and password values and passes them to wp_update_user() as ID and user_pass, allowing an unauthenticated attacker to replace any user's password, including an administrator's, and take over the account.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-12981
CAFEHAUS API exposes an unauthenticated password-change route
CAFEHAUS API through 1.0.0 registers POST /wp-json/cafe/v1/user/password/update without a permission_callback. The public handler accepts attacker-controlled userId and password values and passes them to wp_update_user() as ID and user_pass, allowing an unauthenticated attacker to replace any user's password, including an administrator's, and take over the account.
|
See mitigation notes |
CVE9.8
NVDPending
|