WordPress Plugin Vulnerabilities

WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization

Description

The plugin does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.

Proof of Concept

Affects Plugins

Fixed in 3.0.18

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
ABIODUN VICTOR TAIWO
Submitter
ABIODUN VICTOR TAIWO
Verified
Yes

Timeline

Publicly Published
2026-08-24 (about 3 days ago)
Added
2026-08-24 (about 2 days ago)
Last Updated
2026-08-24 (about 2 days ago)

Other