Impact
The WP Cafe Pro plugin versions earlier than 3.0.15 contain an unauthenticated sensitive data exposure flaw. An attacker who can reach the plugin’s HTTP endpoints can read private information that the plugin stores or reveals through its API or configuration pages. The vulnerability is caused by missing authentication checks around those endpoints, allowing the collection of personal data, transaction records, or other confidential content hosted on the WordPress site.
Affected Systems
The vulnerability affects the WPCafe WP Cafe Pro plugin installed on any WordPress website. Any instance running a version older than 3.0.15 is at risk, regardless of the WordPress core or other plugin versions.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity. Because the flaw is accessible without credentials, the risk of exploitation is potentially high even though EPSS data is not available. The vulnerability is not listed in the CISA KEV catalog, but this does not reduce the urgency of remediation. Attackers would simply need to locate the plugin’s endpoint and retrieve the exposed data.
OpenCVE Enrichment