Impact
The WPCafe WordPress plugin versions 3.0.10 through 3.0.17 fail to enforce proper access control on because the permission callbacks return an incorrect type when a user does not meet the required privileges, allowing any visitor to retrieve guest order information, change order status, or move orders to trash. This flaw exposes sensitive order details to the public and undermines the integrity of the order system, potentially enabling fraud or data loss. The weakness is a classic case of improper authorization.
Affected Systems
The vulnerability affects the WPCafe WordPress plugin for versions before 3.0.18. The affected product is the WPCafe plugin installed on a WordPress site; versions 3.0.10 through 3.0.17 are impacted.
Risk and Exploitability
The flaw is exploitable by any attacker who can reach the site’s REST API, which is normally accessible over the web, and requires no authentication. The CVSS score of 6.5 indicates a medium‑to‑high severity. Although an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the impact on confidentiality and integrity, combined with a simple network‑level attack vector, suggests a high risk assessment.
OpenCVE Enrichment