Wpcafe

WordPress plugin · wpcafe · WordPress.org ↗
0
Critical
0
High
2
Known total
0
Unfixed
Running Wpcafe on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 6.5
WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API
CVE.org
>=3.0.10, <3.0.18 v3.0.18 CVE-2026-86812 Sep 11, 2026
MEDIUM
CVSS 5.3
WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization
CVE.org
>=0, <3.0.18 v3.0.18 CVE-2026-14550 Aug 26, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.