PT-2026-104540 · WordPress · Wpcafe

·

CVE-2026-11601

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System versions prior to 3.0.20
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. This allows unauthenticated attackers to read, create, update, clone, and delete email notification flows. Attackers can overwrite default reservation confirmation, cancellation, and admin alert emails with malicious content sent from the site's legitimate address or completely destroy reservation notification flows. The issue is present because the Email Automation Service Provider::is enable() function unconditionally returns true, and the plugin includes five pre-configured default email flows upon activation.
Recommendations Update WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System to version 3.0.20 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11601

Affected Products

Wpcafe