๐Ÿ” CVE Alert

CVE-2026-14550

MEDIUM 5.3

WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization

CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
9th

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.

Vendor unknown
Product wpcafe
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpcafe

Be the first to know when new medium vulnerabilities affecting unknown wpcafe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPCafe
0 < 3.0.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/98d547aa-6060-45d0-9cf6-cc9092dcc7d2/

Credits

ABIODUN VICTOR TAIWO WPScan