CVE-2026-11601
Received Received - Intake

Authorization Bypass in WPCafe WordPress Plugin

Vulnerability report for CVE-2026-11601, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site's legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpcafe restaurant_menu_online_food_ordering_and_table_booking_system to 3.0.19 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPCafe WordPress plugin has an authorization bypass flaw in versions up to 3.0.19. Unauthenticated attackers can manipulate email notification flows, including overwriting reservation emails or deleting flows entirely. The issue occurs because the plugin does not verify user permissions before allowing actions.

Detection Guidance

Check for unauthorized modifications to email notification flows in the WPCafe plugin settings. Inspect WordPress logs for unusual activity related to email automation endpoints. Verify if default reservation emails have been altered or deleted.

Impact Analysis

Attackers could send fake reservation confirmations or cancellations from your site's legitimate email address. They might also delete all reservation notifications, disrupting your business operations. The vulnerability requires no special configuration to exploit.

Compliance Impact

This could violate GDPR by exposing users to phishing via fake emails or failing to provide proper reservation confirmations. For HIPAA, unauthorized email modifications might compromise protected health information notifications. Compliance depends on the specific use case and data involved.

Mitigation Strategies

Update the WPCafe plugin to the latest version beyond 3.0.19. Disable email automation features if not required. Review and restore default reservation emails if they have been tampered with. Monitor for suspicious activity in email logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11601. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart