Skip to content
Threat Feed
high advisory

Local File Inclusion in WPCafe WordPress Plugin (CVE-2026-75028)

The WPCafe WordPress plugin contains a local file inclusion vulnerability in its template scope function, allowing authenticated contributors to execute arbitrary PHP files.

CVE search metadata

CVE search record: CVE-2026-75028. Severity: high. CVSS: 7.5. KEV: no. Product: WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System (<= 3.0.18). Brief: Local File Inclusion in WPCafe WordPress Plugin (CVE-2026-75028). Brief link: https://feed.craftedsignal.io/briefs/2026-10-wpcafe-lfi/

The WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to local file inclusion (LFI) in all versions up to and including 3.0.18. The vulnerability resides within the template scope function of the plugin. An attacker with authenticated contributor-level access or higher can leverage this flaw to include and execute arbitrary .php files located on the server. If an attacker manages to upload a malicious PHP file to the server through other vectors, this vulnerability provides a mechanism to execute that code, potentially leading to a full system compromise. This issue affects any WordPress environment running the vulnerable plugin version and requires immediate patching to the latest available release.

Attack Chain

  1. Attacker obtains authenticated access to a WordPress site as a user with contributor privileges or higher.
  2. Attacker uploads a malicious PHP file to a directory on the server, often leveraging separate file upload vectors if available.
  3. Attacker identifies the path to the uploaded malicious file.
  4. Attacker crafts a request targeting the WPCafe plugin template scope function, injecting the path of the malicious PHP file.
  5. The plugin fails to properly validate the template parameter, leading to the inclusion of the attacker-specified file.
  6. The server interprets and executes the arbitrary PHP code contained within the included file.
  7. Attacker gains code execution on the underlying server to achieve persistence or data exfiltration.

Impact

Successful exploitation allows authenticated attackers to execute arbitrary PHP code on the server, potentially leading to unauthorized data access, privilege escalation, and full site compromise. This vulnerability poses a significant risk to restaurant and service-based businesses relying on the WPCafe plugin for online ordering and booking operations.

Recommendation

  • Patch the WPCafe plugin to the latest version immediately to remediate CVE-2026-75028.
  • Conduct a site-wide audit for unauthorized PHP files in common upload directories, such as /wp-content/uploads/.
  • Review access control logs for unusual activity from contributor-level accounts, particularly those interacting with plugin-specific parameters.
  • Utilize WordPress security auditing tools to scan for known vulnerabilities and ensure plugin configurations follow the principle of least privilege.

Immediate actions

Patch WPCafe plugin to version 3.0.19 or later

IT Operations 24h

Threat Hunt

Search for POST/GET requests targeting WPCafe plugin endpoints with suspicious file paths in parameters

T1210 medium medium confidence hunt now

Data: Web server access logs

Mitigations

Upgrade WPCafe plugin

immediate IT Operations

CVE-2026-75028