WPCafe Plugin Vulnerable to Local File Inclusion Attacks
CVE-2024-5431
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 25 June 2024
What is CVE-2024-5431?
The WPCafe plugin for WordPress, specifically the Online Food Ordering, Restaurant Menu, Delivery, and Reservations feature, contains a Local File Inclusion vulnerability. This issue is present in all plugin versions up to and including 2.2.25 and is exploited via the 'reservation_extra_field' shortcode parameter. Authenticated attackers with Contributor-level access or higher can leverage this vulnerability to include remote files on the server, which may result in unauthorized code execution. This susceptibility could severely compromise the security of the affected systems and necessitates immediate attention for those using the plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce * <= 2.2.25
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved