CVE-2026-14550
WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization
CVSS Score
5.3
EPSS Score
0.2%
EPSS Percentile
9th
The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.
| Vendor | unknown |
| Product | wpcafe |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpcafe
Be the first to know when new medium vulnerabilities affecting unknown wpcafe are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPCafe
0 < 3.0.18
References
Credits
ABIODUN VICTOR TAIWO WPScan