Local File Inclusion Vulnerability in WP Cafe Pro Plugin by WordPress
CVE-2026-66586

6.6MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-66586?

The WP Cafe Pro plugin versions prior to 3.0.15 contain a Local File Inclusion vulnerability that could allow an attacker to access sensitive files on the server. This security issue arises from insufficient validation of user inputs, allowing attackers to manipulate file paths. Website owners using affected versions are advised to update to the latest version immediately to mitigate potential security risks.

Affected Version(s)

WP Cafe Pro < 3.0.15

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.