← Terug naar overzicht

A critical unauthenticated Local File Inclusion (LFI) vulnerability has been identified in WP Cafe Pro, a WordPress plugin, affecting versions prior to 3.0.15. The vulnerability allows unauthenticated attackers to include local files on the server, potentially exposing sensitive data or enabling remote code execution. No authentication is required to exploit this flaw, making it particularly dangerous. The issue has been assigned CVE-2026-66587 and is tracked by both NVD and Patchstack. Users are strongly advised to update to version 3.0.15 or later to remediate the vulnerability. The vulnerability was catalogued by Patchstack as part of their WordPress security monitoring program. LFI vulnerabilities can be leveraged to read sensitive configuration files, credentials, or execute malicious payloads. The unauthenticated nature of this vulnerability significantly raises its risk profile.

Affected products

  • WP Cafe Pro < 3.0.15

Related CVE's

  • CVE-2026-66587

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities