Arraytics Wp Cafe
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Arraytics Wp Cafe.
By the Year
In 2026 there have been 3 vulnerabilities in Arraytics Wp Cafe with an average score of 6.3 out of ten. Last year, in 2025 Wp Cafe had 1 security vulnerability published. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 6.27 |
| 2025 | 1 | 0.00 |
It may take a day or so for new Wp Cafe vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Arraytics Wp Cafe Security Vulnerabilities
WPCafe 3.0.14 Auth Bypass on Notification Workflows via WP REST Nonce
CVE-2026-11818
5.4 - Medium
- July 10, 2026
The WPCafe Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to list, create, update, delete, clone, and bulk-delete notification flow workflows that are intended to be managed only by administrators. The only protection on these endpoints is a wp_rest nonce check, which is obtainable by any logged-in user from the frontend page source.
AuthZ
WPCafe Plugin 3.0.14 Subscriber Broken Access Control (CVE-2026-57622)
CVE-2026-57622
4.3 - Medium
- June 26, 2026
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
AuthZ
Arraytics WPCafe missing auth in wpcafe <=3.0.7
CVE-2026-27071
9.1 - Critical
- March 25, 2026
Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 3.0.7.
AuthZ
WPCafe <2.2.31: PHP LFI via Improper File Include Control
CVE-2025-30829
- March 27, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics WPCafe wp-cafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through <= 2.2.31.
Remote file include
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Arraytics Wp Cafe or by Arraytics? Click the Watch button to subscribe.