๐Ÿ” CVE Alert

CVE-2026-86812

MEDIUM 6.5

WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.

Vendor unknown
Product wpcafe
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpcafe

Be the first to know when new medium vulnerabilities affecting unknown wpcafe are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPCafe
3.0.10 < 3.0.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fe8d76b2-6d57-49cc-9927-5231e1a26a41/

Credits

Artus KG WPScan