← Terug naar overzicht

A critical unauthenticated Local File Inclusion (LFI) vulnerability has been identified in the WP Cafe Pro WordPress plugin affecting versions prior to 3.0.15. The vulnerability allows unauthenticated attackers to include local files on the server, potentially leading to sensitive information disclosure, code execution, or full system compromise. No authentication is required to exploit this vulnerability, significantly increasing its risk. The issue has been assigned CVE-2026-66587 and is documented in both the NVD and Patchstack databases. Users of WP Cafe Pro are strongly advised to update to version 3.0.15 or later to remediate the vulnerability. The unauthenticated nature of the exploit makes it particularly dangerous for sites running outdated versions of the plugin.

Affected products

  • WP Cafe Pro < 3.0.15

Related CVE's

  • CVE-2026-66587

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities