Local File Inclusion Vulnerability in WPCafe Plugin for WordPress
CVE-2026-75028

7.5HIGH

What is CVE-2026-75028?

The WPCafe plugin is susceptible to a Local File Inclusion vulnerability that can be exploited by authenticated users with contributor-level access and above. This flaw allows attackers to include and execute arbitrary PHP files on the server due to insufficient input validation in the template scope function. Exploiting this vulnerability can lead to unauthorized code execution, bypassing of access controls, and exposure of sensitive data. It is crucial for users of the plugin to upgrade to the latest version to mitigate any risks associated with this security issue.

Affected Version(s)

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System 0 <= 3.0.18

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.