Authorization Bypass Vulnerability in WPCafe Restaurant Menu Plugin for WordPress
CVE-2026-11601
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-11601?
The WPCafe β Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is exposed to an authorization bypass vulnerability. All versions up to and including 3.0.19 fail to properly verify user permissions, allowing unauthenticated attackers to manipulate email notification flows. This could enable attackers to read, create, update, or delete email flows, including replacing critical reservation confirmation and cancellation emails with content of their choice, all sent from the site's legitimate email address. Notably, the vulnerable endpoints are activated by default upon plugin installation and do not require additional configuration, making them an easy target for exploitation.
Affected Version(s)
WPCafe β Restaurant Menu, Online Food Ordering & Table Booking System 0 <= 3.0.19