Executive brief
WP Cafe Pro is a WordPress plugin used to manage cafe and restaurant operations on WordPress sites. An unauthenticated local file inclusion vulnerability allows attackers to read sensitive server files without logging in, potentially exposing database credentials, configuration files, or other confidential data stored on the server.
Technical details
This is a local file inclusion (LFI) vulnerability in WP Cafe Pro versions before 3.0.15, exploitable without authentication. The vulnerability allows attackers to manipulate plugin parameters to include and read arbitrary files from the server filesystem. The attack requires only network access to the WordPress site and no user interaction or prior authentication. Successful exploitation can lead to information disclosure of sensitive files, including database credentials and configuration data that may facilitate further attacks. The vulnerability is patched in version 3.0.15 and later.
Affected products
- WP Cafe Pro WP Cafe Pro < 3.0.15
Timeline
- 2026-08-20: disclosed
- 2026-08-24: advisory