Sceawere
Vulnerability Detail
CVE-2026-75028UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPCafe Plugin Local File Inclusion
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- arraytics
- Product
- WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
- Attack Type
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-03T07:16:48.160Z",
"pubdate": "2026-10-03T07:16:48.160Z",
"executiveSummary": "The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress contains a critical Local File Inclusion (LFI) vulnerability in all versions up to, and including, 3.0.18.\nThis vulnerability originates from improper handling of user-supplied input within the plugin's template scope function.\nThe flaw allows authenticated attackers with contributor-level privileges or higher to include and execute arbitrary PHP files located on the server.\nSuccessful exploitation results in Remote Code Execution (RCE), allowing the attacker to bypass access controls, exfiltrate sensitive configuration files, interact with the underlying database, or gain complete control over the WordPress environment.\nThe risk is severe as it permits lateral movement and full system compromise if an attacker can manipulate or upload files that are subsequently processed by the vulnerable function.",
"technicalDetails": "The vulnerability is localized within the plugin's template handling mechanism, specifically residing in the (template scope) function. The root cause of this LFI is the insecure use of user-supplied data to determine the file path for inclusion operations. The function fails to perform adequate input validation or path sanitization, allowing for directory traversal sequences or the targeting of arbitrary file paths within the WordPress filesystem.\nAn attacker possessing at least contributor-level privileges can interact with the vulnerable component to influence the server-side file inclusion process. By providing a crafted payload to the affected parameter, an attacker can coerce the PHP include() or require() functions into executing arbitrary code residing in local files. If the attacker has previously successfully uploaded a malicious PHP file to the server (e.g., via other plugin functionalities or media uploads), they can trigger its execution by pointing the template scope function to the path of the uploaded file.\nThe attack flow proceeds as follows: 1) The authenticated attacker identifies the vulnerable function parameter handling template paths. 2) The attacker crafts an HTTP request incorporating a file path that points to a target PHP file. 3) The server-side code, failing to validate the input, passes this malicious path to the filesystem inclusion function. 4) The PHP interpreter executes the code within the included file, granting the attacker the effective privileges of the web server process.\nThe scope of impact is significant because the vulnerability effectively bypasses WordPress's intended operational logic. Once the attacker achieves code execution, they can execute system-level commands, modify the WordPress database to elevate their own privileges, or inject malicious scripts into existing site templates. This vulnerability poses a critical risk in shared hosting environments where cross-site directory traversal might be possible, or in scenarios where the filesystem contains other attacker-controllable input points, such as log files or profile image uploads that can be treated as PHP executable content."
}