Junglewise Threat Intelligence

CVE-2026-40796: WPPizza sensitive data exposure in WordPress plugin

CVE-2026-40796 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

WPPizza is a popular WordPress plugin used by restaurants to manage online food orders and menus. A security flaw in versions 3.19.9 and earlier allows users with basic 'Subscriber' accounts to access sensitive system information that should be restricted. This exposure could provide attackers with the technical details needed to launch more sophisticated attacks against the website or its customers.

Technical details

WPPizza versions <= 3.19.9 are vulnerable to sensitive data exposure (CWE-497). The vulnerability allows an authenticated attacker with low-level privileges, such as a Subscriber, to access sensitive system information that is normally restricted to higher-level roles. The attack is carried out over the network and does not require user interaction. This exposure can be leveraged to gain insights into the system's configuration or to facilitate further exploitation of the WordPress environment. The issue is resolved in version 3.20.

Affected products

  • WPPizza WPPizza <= 3.19.9

Timeline

  • 2026-03-30: other: Vulnerability reported by researcher Muhan Luo
  • 2026-04-29: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published in NVD
  • 2026-04-29: patched: Version 3.20 released to address the vulnerability

References