WPCafe
cpe:2.3:a:themewinter:wpcafe:*:*:*:*:wordpress:*:*
- <= 3.0.14
A vulnerability exists in the WPCafe WordPress plugin, specifically in the Restaurant Menu, Online Food Ordering & Table Booking System version 3.0.14 and earlier. The issue stems from the plugin's failure to properly verify user authorization for certain actions. This flaw enables authenticated users with subscriber-level access and above to manipulate notification flow workflows—such as listing, creating, updating, deleting, cloning, and bulk-deleting—tasks that should be restricted to administrators. The only safeguard on these endpoints is a wp_rest nonce check, which any logged-in user can access from the frontend page source.
Exploitation of this vulnerability allows for unauthorized users to make arbitrary modifications to notification flow workflows via the REST API, potentially disrupting site functionality or user experience.
To reproduce this vulnerability, an authenticated user with subscriber-level access can send requests to the WPCafe REST API endpoints for notification flows. The requests can include the wp_rest nonce, which is available in the frontend page source. Once the requests are sent, the user can perform actions such as creating, updating, deleting, cloning, or bulk-deleting notification flows, bypassing the intended authorization restrictions.
Users are advised to update the WPCafe WordPress plugin to version 3.0.15 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.