Access Control Issue in WPCafe Plugin by WordPress
CVE-2026-86812
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-86812?
The WPCafe plugin for WordPress prior to version 3.0.18 has a vulnerability that compromises access control for specific order-management REST endpoints. This issue arises from incorrect permission callbacks that fail to appropriately restrict access. As a result, unauthenticated users may gain access to sensitive guest order information and have the ability to alter order status or delete orders without proper authentication. This flaw poses a significant risk, enabling unauthorized manipulation of order data.
Affected Version(s)
WPCafe 3.0.10 < 3.0.18
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.