8.8
CVE-2024-5431
- EPSS 1.41%
- Veröffentlicht 25.06.2024 06:15:11
- Zuletzt bearbeitet 06.03.2025 14:25:09
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, potentially resulting in code execution
Mögliche Gegenmaßnahme
Restaurant Menu, Online Food Ordering and Reservation Booking Plugin – WPCafe: Update to version 2.2.26, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Restaurant Menu, Online Food Ordering and Reservation Booking Plugin – WPCafe
Version
*-2.2.25
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themewinter ≫ Wpcafe SwPlatformwordpress Version < 2.2.26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.41% | 0.799 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|