WPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST API
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.5epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Unknown · WPCafepublic PoCs found — 1
cve_referencewpscan.com/vulnerability/fe8d76b2-6d57-49cc-9927-5231e1a26a41/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.