Description
WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce version 2.2.25 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.26 or latest
References
Related Vulnerabilities
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Cross-Site Request Forgery (1.18.0)
WordPress Plugin WP Maintenance Mode Multiple Vulnerabilities (2.0.3)
WordPress Plugin Cartogiraffe Map Cross-Site Scripting (1.0)
WordPress Plugin PopCash.Net Code Integration Tool Cross-Site Scripting (1.0)
WordPress Plugin Email Artillery (MASS EMAIL) Multiple Vulnerabilities (4.1)