CVE-2026-66585 HIGH

CVE-2026-66585: WordPress WP Cafe Pro plugin < 3.0.15 - Sensitive Data Exposure vulnerability

Vendor Wpcafe
Product WP Cafe Pro
Weakness CWE-201
Published August 24, 2026
Last update August 24, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

Explanation of Vulnerability in Simple Terms

02Summary

WP Cafe Pro versions before 3.0.15 leak sensitive information in outbound network traffic. An unauthenticated attacker on the network can intercept and read this data without user interaction. The vulnerability affects all versions prior to 3.0.15. Site administrators should update immediately to patch the information disclosure.

What an attacker can do

03Attacker Capabilities

Read sensitive information from network traffic sent by the site.

Potential impact on your site

04Site Impact

Sensitive data may be exposed to anyone monitoring network traffic to or from your site.

Conditions required to exploit

05Prerequisites

Network access to intercept traffic; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 24, 2026 CVE published