Sceawere
Vulnerability Detail
CVE-2026-11601UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPCafe Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- arraytics
- Product
- WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site's legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-03T07:16:47.380Z",
"pubdate": "2026-10-03T07:16:47.380Z",
"executiveSummary": "The WPCafe WordPress plugin contains a critical authorization bypass vulnerability affecting all versions up to and including 3.0.19.\nThe vulnerability stems from improper access control validation within the plugin's email notification management system, allowing unauthenticated remote attackers to perform unauthorized administrative actions.\nImpact includes the ability to read, create, modify, clone, and delete sensitive email notification flows, such as reservation confirmations and administrative alerts.\nAttackers can leverage this to inject malicious content into automated communications sent from the victim's site, potentially facilitating phishing or social engineering campaigns.\nThe vulnerability is active by default upon installation, as the Email_Automation_Service_Provider::is_enable() method returns a static true value, bypassing the need for specific configuration.\nExploitation does not require prior authentication or elevated privileges, significantly increasing the risk to any site utilizing the plugin.",
"technicalDetails": "The vulnerability resides within the plugin's email automation framework, specifically targeting the logic responsible for handling notification flow management.\nThe root cause is a lack of rigorous authorization checks on sensitive REST API or internal action endpoints. The plugin fails to verify user roles or permissions before processing requests related to email flow CRUD (Create, Read, Update, Delete) operations.\nThe component Email_Automation_Service_Provider::is_enable() is programmed to unconditionally return true. Consequently, the affected endpoints remain accessible to external requests by default, regardless of the site's security configuration or administrator settings.\nAn unauthenticated attacker can interact directly with the vulnerable endpoints to manipulate the site's email notification logic. By sending crafted HTTP requests, an attacker can overwrite existing reservation confirmation, cancellation, and admin alert templates.\nThe attack flow follows a direct manipulation pattern: 1) The attacker probes the API endpoints responsible for email automation. 2) Due to the lack of nonce validation or capability checking (e.g., current_user_can('manage_options')), the request is processed by the server. 3) The attacker submits a malicious payload containing modified email subject lines, body content, or workflow parameters. 4) The server updates the internal database records for these notifications. 5) Subsequent legitimate user interactions (such as making a table booking) trigger these compromised workflows, causing the system to dispatch attacker-controlled emails from the legitimate site domain.\nPost-exploitation impact is significant, as it enables persistent modification of site behavior. Attackers can effectively hijack the communication channel between the restaurant and its customers. This can be used to redirect users to malicious URLs, intercept reservation data, or perform site-wide denial of service by destroying the default notification flows necessary for business operations.\nThe vulnerability is pervasive across all versions up to 3.0.19, as the core architectural flaw regarding authorization enforcement is consistent throughout this version range.\nThe vulnerability is network-exposed, requiring only connectivity to the WordPress site's web server to execute the bypass."
}