CVE-2026-86812
WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.
| Vendor | unknown |
| Product | wpcafe |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpcafe
Be the first to know when new medium vulnerabilities affecting unknown wpcafe are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPCafe
3.0.10 < 3.0.18
References
Credits
Artus KG WPScan