Description
WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce version 2.2.25 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.26 or latest
References
Related Vulnerabilities
MODX Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-9069)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-7836)
WordPress Plugin Learning Courses Privilege Escalation (4.7)
WordPress Plugin Request Quote via Whatsapp for Woocommerce Cross-Site Scripting (1.0.1)