{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpcaferestaurant_menu_online_food_ordering_table_booking_system/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpcafe:restaurant_menu_online_food_ordering_table_booking_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75028"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPCafe – Restaurant Menu, Online Food Ordering \u0026 Table Booking System (\u003c= 3.0.18)"],"_cs_severities":["high"],"_cs_tags":["wordpress","lfi","cve-2026-75028"],"_cs_type":"advisory","_cs_vendors":["WPCafe"],"content_html":"\u003cp\u003eThe WPCafe - Restaurant Menu, Online Food Ordering \u0026amp; Table Booking System plugin for WordPress is vulnerable to local file inclusion (LFI) in all versions up to and including 3.0.18. The vulnerability resides within the template scope function of the plugin. An attacker with authenticated contributor-level access or higher can leverage this flaw to include and execute arbitrary .php files located on the server. If an attacker manages to upload a malicious PHP file to the server through other vectors, this vulnerability provides a mechanism to execute that code, potentially leading to a full system compromise. This issue affects any WordPress environment running the vulnerable plugin version and requires immediate patching to the latest available release.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains authenticated access to a WordPress site as a user with contributor privileges or higher.\u003c/li\u003e\n\u003cli\u003eAttacker uploads a malicious PHP file to a directory on the server, often leveraging separate file upload vectors if available.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the path to the uploaded malicious file.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a request targeting the WPCafe plugin template scope function, injecting the path of the malicious PHP file.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to properly validate the template parameter, leading to the inclusion of the attacker-specified file.\u003c/li\u003e\n\u003cli\u003eThe server interprets and executes the arbitrary PHP code contained within the included file.\u003c/li\u003e\n\u003cli\u003eAttacker gains code execution on the underlying server to achieve persistence or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to execute arbitrary PHP code on the server, potentially leading to unauthorized data access, privilege escalation, and full site compromise. This vulnerability poses a significant risk to restaurant and service-based businesses relying on the WPCafe plugin for online ordering and booking operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the WPCafe plugin to the latest version immediately to remediate CVE-2026-75028.\u003c/li\u003e\n\u003cli\u003eConduct a site-wide audit for unauthorized PHP files in common upload directories, such as /wp-content/uploads/.\u003c/li\u003e\n\u003cli\u003eReview access control logs for unusual activity from contributor-level accounts, particularly those interacting with plugin-specific parameters.\u003c/li\u003e\n\u003cli\u003eUtilize WordPress security auditing tools to scan for known vulnerabilities and ensure plugin configurations follow the principle of least privilege.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-03T08:54:28Z","date_published":"2026-10-03T08:54:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wpcafe-lfi/","summary":"The WPCafe WordPress plugin contains a local file inclusion vulnerability in its template scope function, allowing authenticated contributors to execute arbitrary PHP files.","title":"Local File Inclusion in WPCafe WordPress Plugin (CVE-2026-75028)","url":"https://feed.craftedsignal.io/briefs/2026-10-wpcafe-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpcafe:restaurant_menu_online_food_ordering_table_booking_system:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}