Sceawere

Vulnerability Detail

CVE-2026-11601UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WPCafe Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
arraytics
Product
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site's legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-03T07:16:47.380Z",
  "pubdate": "2026-10-03T07:16:47.380Z",
  "executiveSummary": "The WPCafe WordPress plugin contains a critical authorization bypass vulnerability affecting all versions up to and including 3.0.19.\nThe vulnerability stems from improper access control validation within the plugin's email notification management system, allowing unauthenticated remote attackers to perform unauthorized administrative actions.\nImpact includes the ability to read, create, modify, clone, and delete sensitive email notification flows, such as reservation confirmations and administrative alerts.\nAttackers can leverage this to inject malicious content into automated communications sent from the victim's site, potentially facilitating phishing or social engineering campaigns.\nThe vulnerability is active by default upon installation, as the Email_Automation_Service_Provider::is_enable() method returns a static true value, bypassing the need for specific configuration.\nExploitation does not require prior authentication or elevated privileges, significantly increasing the risk to any site utilizing the plugin.",
  "technicalDetails": "The vulnerability resides within the plugin's email automation framework, specifically targeting the logic responsible for handling notification flow management.\nThe root cause is a lack of rigorous authorization checks on sensitive REST API or internal action endpoints. The plugin fails to verify user roles or permissions before processing requests related to email flow CRUD (Create, Read, Update, Delete) operations.\nThe component Email_Automation_Service_Provider::is_enable() is programmed to unconditionally return true. Consequently, the affected endpoints remain accessible to external requests by default, regardless of the site's security configuration or administrator settings.\nAn unauthenticated attacker can interact directly with the vulnerable endpoints to manipulate the site's email notification logic. By sending crafted HTTP requests, an attacker can overwrite existing reservation confirmation, cancellation, and admin alert templates.\nThe attack flow follows a direct manipulation pattern: 1) The attacker probes the API endpoints responsible for email automation. 2) Due to the lack of nonce validation or capability checking (e.g., current_user_can('manage_options')), the request is processed by the server. 3) The attacker submits a malicious payload containing modified email subject lines, body content, or workflow parameters. 4) The server updates the internal database records for these notifications. 5) Subsequent legitimate user interactions (such as making a table booking) trigger these compromised workflows, causing the system to dispatch attacker-controlled emails from the legitimate site domain.\nPost-exploitation impact is significant, as it enables persistent modification of site behavior. Attackers can effectively hijack the communication channel between the restaurant and its customers. This can be used to redirect users to malicious URLs, intercept reservation data, or perform site-wide denial of service by destroying the default notification flows necessary for business operations.\nThe vulnerability is pervasive across all versions up to 3.0.19, as the core architectural flaw regarding authorization enforcement is consistent throughout this version range.\nThe vulnerability is network-exposed, requiring only connectivity to the WordPress site's web server to execute the bypass."
}
CVE-2026-11601: WPCafe Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere