Authorization Bypass Vulnerability in WPCafe Restaurant Menu Plugin for WordPress
CVE-2026-11601

5.3MEDIUM

What is CVE-2026-11601?

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is exposed to an authorization bypass vulnerability. All versions up to and including 3.0.19 fail to properly verify user permissions, allowing unauthenticated attackers to manipulate email notification flows. This could enable attackers to read, create, update, or delete email flows, including replacing critical reservation confirmation and cancellation emails with content of their choice, all sent from the site's legitimate email address. Notably, the vulnerable endpoints are activated by default upon plugin installation and do not require additional configuration, making them an easy target for exploitation.

Affected Version(s)

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System 0 <= 3.0.19

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Kochan
.