WordPress security by component
wpcafe
Plugin description
wpcafe provides restaurant menu, food ordering, reservation, and related café management features for WordPress.
wpcafe (wpcafe) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
wpcafeLatest vulnerability
CVE-2026-86812: WPCafe exposes guest orders to unauthenticated manipulation
WPCafe before 3.0.18 returns the wrong failure type from permission callbacks on order-management REST endpoints. WordPress therefore permits unauthenticated callers to read guest order information and to change the status of, or trash, arbitrary orders. The authoritative export identifies the affected endpoint group and permission-callback failure but does not disclose the route or parameter names.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-86812
WPCafe exposes guest orders to unauthenticated manipulation
WPCafe before 3.0.18 returns the wrong failure type from permission callbacks on order-management REST endpoints. WordPress therefore permits unauthenticated callers to read guest order information and to change the status of, or trash, arbitrary orders. The authoritative export identifies the affected endpoint group and permission-callback failure but does not disclose the route or parameter names.
|
3.0.18 |
CVE6.5
NVDPending
|
| Dec 09, 2024 |
CVE-2023-47805
WPCafe: A security weakness
WPCafe is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD9.8
|