Description
WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce version 2.2.23 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.24 or latest
References
Related Vulnerabilities
WordPress Plugin Comment Link Remove and Other Comment Tools Cross-Site Request Forgery (2.1.4)
WordPress Plugin Starbox-the Author Box for Humans Cross-Site Scripting (3.0.8)
Apache Traffic Server Out-of-bounds Write Vulnerability (CVE-2021-35474)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2019-19880)