CVE-2026-86816
Received Received - Intake

Unauthenticated Access to WooCommerce Data in WPCafe

Vulnerability report for CVE-2026-86816, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: WPScan

Description

The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown WPCafe 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPCafe WordPress plugin before version 3.0.21 has unrestricted REST API endpoints that allow unauthenticated attackers to access sensitive WooCommerce product data. This includes per-product sales counts, exact stock levels, and private product metadata that WooCommerce normally restricts to authenticated users.

Detection Guidance

Check if your WPCafe plugin version is below 3.0.21 by inspecting the plugin files or WordPress admin panel. Use tools like WPScan to detect vulnerable endpoints by scanning for unrestricted REST API access in the WPCafe plugin.

Impact Analysis

Attackers could exploit this to read confidential business data like sales figures and inventory levels without authentication. This could lead to competitive disadvantages, financial loss, or misuse of sensitive product information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing sensitive product data such as stock levels and sales counts without proper authentication. Unauthorized access to private product metadata may violate data protection requirements for handling personal or sensitive information.

Mitigation Strategies

Update the WPCafe plugin to version 3.0.21 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Review and restrict access to sensitive WooCommerce product data through proper authentication mechanisms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86816. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart