Impact
An unauthenticated local file inclusion vulnerability exists in WP Cafe Pro versions earlier than 3.0.15, which allows an attacker to read arbitrary files on the server. This flaw could lead to exposure of sensitive data such as configuration files or credentials. The weakness stems from improper validation of user‑supplied file paths, classified as CWE-98. Based on the description, it is inferred that the vulnerability can be triggered via standard HTTP requests, requiring no user authentication.
Affected Systems
The affected product is the WordPress plugin WP Cafe Pro from the vendor WPCafe, specifically all released versions with a version number lower than 3.0.15.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity, and the EPSS score is not available, indicating that the exploitation probability is currently unknown. Based on the description, it is inferred that the vulnerability can be triggered via standard HTTP requests and requires no user authentication; this makes any web visitor a potential attacker. The absence of a CISA KEV listing does not reduce its danger—WordPress sites remain a common attack surface for LFI.
OpenCVE Enrichment