Junglewise Threat Intelligence

CVE-2026-66585: WP Cafe Pro unauthenticated sensitive data exposure

CVE-2026-66585 · Severity: high · CVSS 7.5 · Published 2026-08-24

Technologies: WP Cafe Pro. Vendors: WP Cafe.

Executive brief

WP Cafe Pro is a WordPress plugin that provides cafe management functionality. The plugin contains an unauthenticated vulnerability that allows attackers to access sensitive data such as passwords, emails, and payment information without requiring any credentials, potentially exposing customer and business data to unauthorized parties.

Technical details

This is a sensitive data exposure vulnerability in WP Cafe Pro versions prior to 3.0.15. The vulnerability allows unauthenticated attackers to access sensitive information; no authentication is required to exploit it. The attack is network-accessible and requires no special preconditions. Successful exploitation exposes private data including passwords, email addresses, and payment details. The vulnerability has been patched in version 3.0.15 and later. Patchstack has provided a mitigation rule to block exploitation attempts.

Affected products

  • WP Cafe WP Cafe Pro < 3.0.15

Timeline

  • 2026-08-24: disclosed
  • 2026-08-20: patched: Version 3.0.15 released

References

Related threats