CVE-2025-39452
- EPSS 0.42%
- Veröffentlicht 17.04.2025 15:15:42
- Zuletzt bearbeitet 17.04.2025 20:21:05
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion. This issue affects WPCafe: from n/a through 2.2.32.
CVE-2025-30829
- EPSS 0.42%
- Veröffentlicht 27.03.2025 10:55:18
- Zuletzt bearbeitet 27.03.2025 16:45:12
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion. This issue affects WPCafe: from n/a through 2.2.31.
CVE-2023-47805
- EPSS 0.71%
- Veröffentlicht 09.12.2024 13:15:30
- Zuletzt bearbeitet 04.03.2025 18:19:12
Missing Authorization vulnerability in Themewinter WPCafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through 2.2.22.
CVE-2024-43135
- EPSS 1.66%
- Veröffentlicht 13.08.2024 11:15:19
- Zuletzt bearbeitet 12.09.2024 21:18:15
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.
CVE-2024-37513
- EPSS 1.23%
- Veröffentlicht 09.07.2024 13:15:10
- Zuletzt bearbeitet 21.11.2024 09:23:58
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue affects WPCafe: from n/a through 2.2.27.
CVE-2024-5431
- EPSS 1.41%
- Veröffentlicht 25.06.2024 06:15:11
- Zuletzt bearbeitet 06.03.2025 14:25:09
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter...
CVE-2024-5427
- EPSS 0.36%
- Veröffentlicht 31.05.2024 07:15:10
- Zuletzt bearbeitet 06.03.2025 14:25:09
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 ...
CVE-2024-1855
- EPSS 0.46%
- Veröffentlicht 23.05.2024 02:15:08
- Zuletzt bearbeitet 06.03.2025 14:25:09
The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission fun...