Description
The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The WPCafe WordPress plugin before version 3.0.21 exposes REST API endpoints without authentication, allowing unauthenticated attackers to read WooCommerce product data that includes per‑product sales counts, exact stock levels, and private product meta. This disclosure compromises the confidentiality of sales and inventory information.

Affected Systems

Any WordPress installation using the WPCafe plugin with a version earlier than 3.0.21 is vulnerable. The vulnerability arises when the plugin’s REST API endpoints are accessed by unauthenticated users.

Risk and Exploitability

Because the CVSS score is not available and EPSS data is missing, the precise exploitation probability cannot be quantified. The likely attack vector is a network‑based request to the plugin’s public REST API endpoints, which can be accessed without credentials. An attacker can simply issue HTTP GET requests to the exposed URLs and retrieve detailed product information, compromising the confidentiality of sales and inventory data. In the absence of further mitigations, the vulnerability remains exploitable by any unauthenticated adversary with network access to the site.

Generated by OpenCVE AI on October 7, 2026 at 07:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the WPCafe plugin to version 3.0.21 or later to eliminate the unauthenticated REST endpoints.
  • If an immediate update is not available, block unauthenticated requests to the affected REST API routes using WordPress role checks or a firewall rule that denies access to those URLs for non‑logged‑in users.
  • Remove the plugin if it is not essential to the site’s functionality.

Generated by OpenCVE AI on October 7, 2026 at 07:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
Title WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:08.124Z

Reserved: 2026-09-08T13:49:57.515Z

Link: CVE-2026-86816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:01.613

Modified: 2026-10-07T07:17:01.613

Link: CVE-2026-86816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control