Impact
The WPCafe WordPress plugin before version 3.0.21 exposes REST API endpoints without authentication, allowing unauthenticated attackers to read WooCommerce product data that includes per‑product sales counts, exact stock levels, and private product meta. This disclosure compromises the confidentiality of sales and inventory information.
Affected Systems
Any WordPress installation using the WPCafe plugin with a version earlier than 3.0.21 is vulnerable. The vulnerability arises when the plugin’s REST API endpoints are accessed by unauthenticated users.
Risk and Exploitability
Because the CVSS score is not available and EPSS data is missing, the precise exploitation probability cannot be quantified. The likely attack vector is a network‑based request to the plugin’s public REST API endpoints, which can be accessed without credentials. An attacker can simply issue HTTP GET requests to the exposed URLs and retrieve detailed product information, compromising the confidentiality of sales and inventory data. In the absence of further mitigations, the vulnerability remains exploitable by any unauthenticated adversary with network access to the site.
OpenCVE Enrichment