天下漏洞,尽知其名
MEDIUM

CVE-2026-11601 WPCafe 授权绕过漏洞

影响未授权攻击者可篡改或删除邮件通知流程,伪造站点邮件内容

AI 研判

WordPress 插件 WPCafe(餐厅菜单、在线订餐与餐桌预订系统)存在授权绕过漏洞。由于插件未正确校验用户是否有权执行相关操作,未认证攻击者可访问邮件自动化相关接口。该漏洞影响 3.0.19 及之前的所有版本。

影响范围

WPCafe

WPCafe 插件所有版本至 3.0.19(含 3.0.19)。

漏洞详情

漏洞属于授权绕过(缺失授权校验)。插件中的 Email_Automation_Service_Provider::is_enable() 方法无条件返回 true,且激活时自带五个默认邮件流程,相关接口默认启用、无需任何配置。未认证攻击者可借此读取、创建、更新、克隆和删除邮件通知流程,包括用攻击者控制的内容覆盖默认的预订确认、取消和管理员告警邮件,或彻底破坏预订通知流程。

利用条件与风险

利用无需认证,且漏洞接口在每台安装 WPCafe 的站点上默认开启,实战中可被批量扫描利用,导致邮件内容被篡改、以站点合法地址发送钓鱼或欺诈邮件,或通知功能失效。

修复建议

官方已发布修复版本,建议升级至 3.0.19 之后的修复版本;暂无公开信息说明具体修复版本号。临时缓解措施包括禁用或限制相关邮件自动化接口访问、在 WAF 侧拦截对相关端点的未授权请求。

原始情报

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, clone, and delete email notification flows, including overwriting the default reservation confirmation, cancellation, and admin alert emails with attacker-controlled content sent from the site’s legitimate address, or destroying reservation notification flows entirely. The vulnerable endpoints are active by default on every WPCafe installation without any configuration requirement, as the Email_Automation_Service_Provider::is_enable() method unconditionally returns true and the plugin ships with five pre-configured default email flows upon activation.