Extension WordPress

Vulnérabilités WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

Cette page rassemble les failles publiées pour WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

12 fiches

CVE-2026-11818 Moyenne · 5,4
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe <= 3.0.14 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that…

Versions affectées

*-3.0.14

Correctif

3.0.15

Publication

09/07/2026

CVE-2026-57622 Moyenne · 4,3
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System <= 3.0.14 – Missing Authorization

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.14. This makes…

Versions affectées

*-3.0.14

Correctif

3.0.15

Publication

25/06/2026

CVE-2026-27071 Moyenne · 5,3
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution <= 3.0.7 – Missing Authorization

The WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.7. This makes…

Versions affectées

*-3.0.7

Correctif

3.0.8

Publication

12/03/2026

CVE-2025-39452 Élevée · 8,8
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe <= 2.2.32 – Authenticated (Contributor+) Local File Inclusion

The WPCafe plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.32. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-2.2.32

Correctif

2.2.33

Publication

17/04/2025

CVE-2025-30829 Élevée · 8,8
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe <= 2.2.31 – Authenticated (Contributor+) Local File Inclusion

The WPCafe plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.31. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-2.2.31

Correctif

2.2.32

Publication

27/03/2025

CVE-2024-43135 Élevée · 8,8
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe <= 2.2.28 – Authenticated (Contributor+) Local File Inclusion

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.28 via the template_file of select blocks. This makes…

Versions affectées

*-2.2.28

Correctif

2.2.29

Publication

07/08/2024

CVE-2024-37513 Élevée · 8,8
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe <= 2.2.27 – Authenticated (Contributor+) Local File Inclusion

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.27. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.2.27

Correctif

2.2.28

Publication

05/07/2024

CVE-2024-5431 Élevée · 8,8
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 – Authenticated (Contributor+) File inclusion via Shortcode

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it…

Versions affectées

*-2.2.25

Correctif

2.2.26

Publication

24/06/2024

CVE-2024-5427 Moyenne · 6,4
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 – Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to…

Versions affectées

*-2.2.24

Correctif

2.2.26

Publication

30/05/2024

CVE-2024-1855 Moyenne · 5,3
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe <= 2.2.23 – Unauthenticated Blind Server-Side Request Forgery

The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes…

Versions affectées

*-2.2.23

Correctif

2.2.24

Publication

22/05/2024

Vulnérabilité Élevée · 7,2
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation <= 2.1.4 – Cross-Site Scripting

The WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including 2.1.4 due to insufficient input sanitization and output escaping on…

Versions affectées

*-2.1.4

Correctif

2.2.0

Publication

06/08/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités