WordPress WPCafe是WordPress基金会的一款CMS插件。 WordPress WPCafe 3.0.14及之前版本存在授权问题漏洞,该漏洞源于未正确验证用户授权,可能导致已认证的攻击者(订阅者及以上权限)列出、创建、更新、删除、克隆和批量删除本应由管理员管理的工作流。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| arraytics | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System | ≤ 3.0.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| arraytics | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System | 0 ~ 3.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12924 | 6.4 MEDIUM | Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_ |
| CVE-2026-13039 | 5.3 MEDIUM | Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST |
No comments yet