Description
WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce version 2.2.25 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.26 or latest
References
Related Vulnerabilities
WordPress Plugin JH 404 Logger Cross-Site Scripting (1.1)
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (3.31)
Oracle JRE CVE-2013-5782 Vulnerability (CVE-2013-5782)
WordPress Improper Input Validation Vulnerability (CVE-2008-5695)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.3.0)