Executive brief
The CAFEHAUS API plugin for WordPress, which provides API functionality for the CAFEHAUS system, contains a critical security flaw. This vulnerability allows anyone on the internet to change the password of any user account, including administrators, without needing to log in. An attacker could use this to take full control of the website, potentially leading to data theft, site defacement, or complete service disruption.
Technical details
The CAFEHAUS API plugin for WordPress (versions up to and including 1.0.0) suffers from a critical authentication bypass and privilege escalation vulnerability. The plugin's password update functionality lacks any authentication or authorization checks. A remote, unauthenticated attacker can exploit this by sending a crafted request to the API to reset the password of any registered user, including those with administrative privileges. Successful exploitation results in complete account takeover and full administrative control over the WordPress site. As of the advisory date, there is no known fix available.
Affected products
- Unknown CAFEHAUS API <= 1.0.0
Timeline
- 2026-07-03: disclosed: Publicly published via WPScan
- 2026-07-24: advisory: NVD published date