Junglewise Threat Intelligence

CVE-2026-57622: Arraytics WPCafe broken access control

CVE-2026-57622 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Technologies: Themewinter WPCafe. Vendors: Arraytics, Themewinter.

Executive brief

WPCafe is a WordPress plugin used by restaurants for online food ordering and table reservations. A security flaw in versions 3.0.14 and earlier allows logged-in users with basic 'Subscriber' permissions to access features or information they should not be able to see. This could lead to unauthorized access to internal plugin settings or customer-related data, potentially impacting business operations and privacy.

Technical details

A broken access control vulnerability exists in the Arraytics WPCafe plugin for WordPress (versions <= 3.0.14) due to missing authorization checks (CWE-862). An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw over the network without user interaction. The vulnerability allows these users to execute actions or access data that should be restricted to higher-privileged roles. The issue is resolved in version 3.0.15.

Affected products

  • Arraytics WPCafe <= 3.0.14

Timeline

  • 2026-06-01: other: Reported by L4m
  • 2026-06-25: advisory: Patchstack published advisory
  • 2026-06-26: disclosed: NVD published date

References

Related threats