Junglewise Threat Intelligence

CVE-2026-66587: WP Cafe Pro local file inclusion

CVE-2026-66587 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Technologies: WP Cafe Pro.

Executive brief

WP Cafe Pro is a WordPress plugin used to manage cafe and restaurant operations on WordPress sites. An unauthenticated local file inclusion vulnerability allows attackers to read sensitive server files without logging in, potentially exposing database credentials, configuration files, or other confidential data stored on the server.

Technical details

This is a local file inclusion (LFI) vulnerability in WP Cafe Pro versions before 3.0.15, exploitable without authentication. The vulnerability allows attackers to manipulate plugin parameters to include and read arbitrary files from the server filesystem. The attack requires only network access to the WordPress site and no user interaction or prior authentication. Successful exploitation can lead to information disclosure of sensitive files, including database credentials and configuration data that may facilitate further attacks. The vulnerability is patched in version 3.0.15 and later.

Affected products

  • WP Cafe Pro WP Cafe Pro < 3.0.15

Timeline

  • 2026-08-20: disclosed
  • 2026-08-24: advisory

References