CVE-2026-86816: WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API
The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPCafe WordPress pluginto a version that resolves this vulnerability.Fixed in 3.0.21
Event History
Frequently Asked Questions
Which installations are exposed?
Installations using the WPCafe WordPress plugin before version 3.0.21 are affected. The disclosure concerns WPCafe REST API endpoints that expose WooCommerce product data without access restrictions.
Does exploitation require an account or user interaction?
No. The vulnerability is network-accessible and can be exploited by an unauthenticated attacker without user interaction.
What information could be disclosed?
An attacker may read WooCommerce product data including per-product sales counts, exact stock levels, and private product metadata that WooCommerce normally protects behind authentication.