Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-14550

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Aug 26, 2026
Vendor unknown

Description

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow.

References