Description
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site's legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of email notification flows
Action: Immediate Patch
AI Analysis

Impact

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin suffers from an authorization bypass flaw (CWE‑862). The flaw allows any user, even those not authenticated, to read, create, update, clone, and delete email notification flows. By overwriting the default reservation confirmation, cancellation and admin alert emails, an attacker can send legitimate‑looking emails from the site’s domain or eliminate important reservation notifications entirely, potentially leading to phishing, reputational damage, or loss of communication with customers.

Affected Systems

All WordPress installations of the WPCafe plugin released up to version 3.0.19 are affected. The plugin ships five preconfigured email flows and enables the Email Automation Service Provider endpoints by default, without requiring any configuration or authentication checks.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while EPSS is not available and the vulnerability has not been listed in the CISA KEV catalog. The attack vector is straightforward: unauthenticated users can send HTTP requests to the plugin’s REST endpoints because the Email_Automation_Service_Provider::is_enable() method always returns true and the endpoints are active on every installation. An attacker who succeeds can manipulate email content sent from the legitimate domain, thereby facilitating phishing or spam, or simply disrupt reservation communications. The risk remains moderate but could become high in environments where reservation emails are critical.

Generated by OpenCVE AI on October 3, 2026 at 08:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WPCafe to the latest version (≥3.0.20), which introduces proper authorization checks for the email notification endpoints.
  • If an upgrade is not immediately possible, disable the Email Automation Service Provider by removing or commenting out the associated code or unchecking the activation option before the plugin updates patch the issue.
  • As a temporary measure, restrict REST API access so that only authenticated users can reach the /wp-json/email-automation/* routes, using a security plugin or custom code that blocks unauthenticated requests to those endpoints.

Generated by OpenCVE AI on October 3, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/core/assets/localize.php#L47 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/core/email-automation/email-automation-service-provider.php#L43 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L138 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L156 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L282 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L58 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.13/vendor/themewinter/email-notification-sdk/src/Utils/Helpers.php#L20 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/core/assets/localize.php#L47 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/core/email-automation/email-automation-service-provider.php#L43 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L138 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L156 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L282 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Flow/FlowAPI.php#L58 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-cafe/tags/3.0.8/vendor/themewinter/email-notification-sdk/src/Utils/Helpers.php#L20 cve-icon cve-icon
https://plugins.trac.wordpress.org/changeset?reponame=&old=3706610%40wp-cafe&new=3706610%40wp-cafe cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/c01a06ca-ba3f-4e61-a17c-86d5e9f53ebf?source=cve cve-icon cve-icon
History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site's legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.
Title WPCafe <= 3.0.19 - Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.202Z

Reserved: 2026-06-08T15:07:27.415Z

Link: CVE-2026-11601

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:37.904Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:47.380

Modified: 2026-10-03T16:16:35.553

Link: CVE-2026-11601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:30:18Z

Weaknesses