Executive brief
WP Cafe Pro is a WordPress plugin used to create and manage online cafes and restaurant websites. A local file inclusion vulnerability allows attackers with author privileges to load and expose sensitive server files, potentially leading to unauthorized access or site compromise.
Technical details
WP Cafe Pro versions prior to 3.0.15 contain a local file inclusion (LFI) vulnerability classified under OWASP A3: Injection. The vulnerability requires author-level privileges to exploit, meaning an authenticated user with author or higher role can trigger the flaw to access arbitrary server files that should not be publicly accessible. An attacker can leverage this to read configuration files, database credentials, or other sensitive data, potentially escalating to full site or server takeover. The vulnerability has been patched in version 3.0.15 and later.
Affected products
- WP Cafe WP Cafe Pro < 3.0.15
Timeline
- 2026-07-01: disclosed: Reported by Ananda Dhakal (Patchstack)
- 2026-08-19: advisory: Published by Patchstack
- 2026-08-20: patched: Fix available in version 3.0.15 and later