The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication.
https://wpscan.com/vulnerability/e644bbb2-aae7-4f7a-baf7-34e578bcee2a/