Impact
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin suffers from an authorization bypass flaw (CWE‑862). The flaw allows any user, even those not authenticated, to read, create, update, clone, and delete email notification flows. By overwriting the default reservation confirmation, cancellation and admin alert emails, an attacker can send legitimate‑looking emails from the site’s domain or eliminate important reservation notifications entirely, potentially leading to phishing, reputational damage, or loss of communication with customers.
Affected Systems
All WordPress installations of the WPCafe plugin released up to version 3.0.19 are affected. The plugin ships five preconfigured email flows and enables the Email Automation Service Provider endpoints by default, without requiring any configuration or authentication checks.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while EPSS is not available and the vulnerability has not been listed in the CISA KEV catalog. The attack vector is straightforward: unauthenticated users can send HTTP requests to the plugin’s REST endpoints because the Email_Automation_Service_Provider::is_enable() method always returns true and the endpoints are active on every installation. An attacker who succeeds can manipulate email content sent from the legitimate domain, thereby facilitating phishing or spam, or simply disrupt reservation communications. The risk remains moderate but could become high in environments where reservation emails are critical.
OpenCVE Enrichment