CVE · Critical

CVE-2026-27071 — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-27071 WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.8 Missing Authorization Critical 9.1 < 3.0.8 3.0.8 2026-03-12

CVE-2026-27071

The WPCafe plugin for WordPress has a security flaw that allows unauthorized users to bypass certain restrictions, enabling them to execute an unintended operation without proper authentication. The issue arises from the absence of a capability check in a specific function within versions 3.0.7 and earlier. This vulnerability can be exploited by unauthenticated attackers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.