Description
The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated disclosure and modification of order data
Action: Patch Now
AI Analysis

Impact

The WPCafe WordPress plugin versions 3.0.10 through 3.0.17 fail to enforce proper access control on because the permission callbacks return an incorrect type when a user does not meet the required privileges, allowing any visitor to retrieve guest order information, change order status, or move orders to trash. This flaw exposes sensitive order details to the public and undermines the integrity of the order system, potentially enabling fraud or data loss. The weakness is a classic case of improper authorization.

Affected Systems

The vulnerability affects the WPCafe WordPress plugin for versions before 3.0.18. The affected product is the WPCafe plugin installed on a WordPress site; versions 3.0.10 through 3.0.17 are impacted.

Risk and Exploitability

The flaw is exploitable by any attacker who can reach the site’s REST API, which is normally accessible over the web, and requires no authentication. The CVSS score of 6.5 indicates a medium‑to‑high severity. Although an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the impact on confidentiality and integrity, combined with a simple network‑level attack vector, suggests a high risk assessment.

Generated by OpenCVE AI on September 11, 2026 at 11:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPCafe plugin to version 3.0.18 or later to apply the corrected permission callbacks.
  • If an immediate upgrade is not possible, restrict external access to the affected REST endpoints, for example by blocking unauthenticated traffic with .htaccess rules or a firewall.
  • Configure WordPress security settings or a dedicated security plugin to monitor and alert on unauthorized order modifications and to limit API exposure.

Generated by OpenCVE AI on September 11, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.
Title WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T10:00:30.098Z

Reserved: 2026-09-08T13:36:19.998Z

Link: CVE-2026-86812

cve-icon Vulnrichment

Updated: 2026-09-11T09:58:37.237Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T07:16:47.737

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-86812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T11:30:12Z

Weaknesses