Access Control Vulnerability in Arraytics WPCafe Plugin
CVE-2026-27071
9.1CRITICAL
What is CVE-2026-27071?
A missing authorization vulnerability in the Arraytics WPCafe plugin allows attackers to exploit incorrectly configured access control settings. This issue impacts WPCafe from its initial release through version 3.0.7, potentially enabling unauthorized actions that compromise the security of WordPress sites utilizing this plugin.
Affected Version(s)
WPCafe 0 <= 3.0.7