Description
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, potentially resulting in code execution
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46653 | The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, potentially resulting in code execution |
References
History
Fri, 10 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:themewinter:wpcafe:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-98 |
Thu, 06 Mar 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themewinter
Themewinter wpcafe |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:themewinter:wpcafe:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themewinter
Themewinter wpcafe |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:55:36.466Z
Reserved: 2024-05-28T13:07:57.937Z
Link: CVE-2024-5431
Updated: 2024-08-01T21:11:12.783Z
Status : Modified
Published: 2024-06-25T06:15:11.800
Modified: 2026-04-08T18:22:04.053
Link: CVE-2024-5431
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD