Impact
Local File Inclusion in the WPCafe WordPress plugin allows authenticated users with contributor-level or higher privileges to include arbitrary .php files via the 'food_menu_style' Elementor widget setting. By crafting a request that points to a hosted PHP file, an attacker can execute that code on the server, potentially bypassing normal access controls, exfiltrating data, or escalating privileges. This issue maps to CWE‑98, which signifies the ability to read or execute local files that should be protected.
Affected Systems
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System developed by arraytics is affected in all releases up to and including version 3.0.18. WordPress sites running this plugin and assigning contributor or higher roles have the exposure. No specific WordPress core versions are mentioned, so all installations using the plugin in these versions are at risk.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity vulnerability. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is local, requiring authenticated access with contributor-level or higher privileges; it is inferred that the attacker would modify the widget setting to point to a malicious PHP file stored on the server. Exploitation complexity appears moderate, as the attacker needs to upload the malicious file via other plugin or upload mechanisms, then adjust the setting, making it accessible with existing administrative privileges.
OpenCVE Enrichment