Description
The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17580 | The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application. |
References
History
Fri, 27 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:themewinter:wpcafe:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Thu, 06 Mar 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themewinter
Themewinter wpcafe |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:themewinter:wpcafe:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themewinter
Themewinter wpcafe |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:56:23.517Z
Reserved: 2024-02-23T17:49:08.261Z
Link: CVE-2024-1855
Updated: 2024-08-01T18:56:22.266Z
Status : Modified
Published: 2024-05-23T02:15:08.277
Modified: 2026-04-08T18:20:52.287
Link: CVE-2024-1855
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD