CVE Database /
CVE-2023-47805
CVE · Medium
CVE-2023-47805 — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.23
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-47805
|
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.23 |
Missing Authorization |
Medium
5.3
|
< 2.2.23
|
2.2.23 |
2023-11-15 |
—
|
CVE-2023-47805
The WPCafe plugin for WordPress versions before 2.2.23 contains a broken access control vulnerability that allows unauthenticated or low-privilege users to perform actions restricted to higher-privilege accounts due to missing authorization checks and nonce verification in certain functions. This flaw was discovered by Abdi Pranata and remains unfixed as of the advisory date. An attacker could exploit this weakness to execute administrative or protected operations without proper authentication or permission validation.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings