Executive brief
WPCafe is a WordPress plugin used by restaurants for online food ordering and table reservations. A security flaw in versions 3.0.14 and earlier allows logged-in users with basic 'Subscriber' permissions to access features or information they should not be able to see. This could lead to unauthorized access to internal plugin settings or customer-related data, potentially impacting business operations and privacy.
Technical details
A broken access control vulnerability exists in the Arraytics WPCafe plugin for WordPress (versions <= 3.0.14) due to missing authorization checks (CWE-862). An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw over the network without user interaction. The vulnerability allows these users to execute actions or access data that should be restricted to higher-privileged roles. The issue is resolved in version 3.0.15.
Affected products
- Arraytics WPCafe <= 3.0.14
Timeline
- 2026-06-01: other: Reported by L4m
- 2026-06-25: advisory: Patchstack published advisory
- 2026-06-26: disclosed: NVD published date