The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-11 07:16
Updated : 2026-09-11 17:35
NVD link : CVE-2026-86812
Mitre link : CVE-2026-86812
CVE.ORG link : CVE-2026-86812
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
