Executive brief
WP Cafe Pro is a WordPress plugin that provides cafe management functionality. The plugin contains an unauthenticated vulnerability that allows attackers to access sensitive data such as passwords, emails, and payment information without requiring any credentials, potentially exposing customer and business data to unauthorized parties.
Technical details
This is a sensitive data exposure vulnerability in WP Cafe Pro versions prior to 3.0.15. The vulnerability allows unauthenticated attackers to access sensitive information; no authentication is required to exploit it. The attack is network-accessible and requires no special preconditions. Successful exploitation exposes private data including passwords, email addresses, and payment details. The vulnerability has been patched in version 3.0.15 and later. Patchstack has provided a mitigation rule to block exploitation attempts.
Affected products
- WP Cafe WP Cafe Pro < 3.0.15
Timeline
- 2026-08-24: disclosed
- 2026-08-20: patched: Version 3.0.15 released