Extension WordPress
Vulnérabilités WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Cette page rassemble les failles publiées pour WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
12 fiches
WPCafe <= 3.0.14 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that…
*-3.0.14
3.0.15
09/07/2026
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System <= 3.0.14 – Missing Authorization
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.14. This makes…
*-3.0.14
3.0.15
25/06/2026
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution <= 3.0.7 – Missing Authorization
The WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.7. This makes…
*-3.0.7
3.0.8
12/03/2026
WPCafe <= 2.2.32 – Authenticated (Contributor+) Local File Inclusion
The WPCafe plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.32. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-2.2.32
2.2.33
17/04/2025
WPCafe <= 2.2.31 – Authenticated (Contributor+) Local File Inclusion
The WPCafe plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.31. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…
*-2.2.31
2.2.32
27/03/2025
WPCafe <= 2.2.28 – Authenticated (Contributor+) Local File Inclusion
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.28 via the template_file of select blocks. This makes…
*-2.2.28
2.2.29
07/08/2024
WPCafe <= 2.2.27 – Authenticated (Contributor+) Local File Inclusion
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.27. This makes it possible for authenticated attackers, with…
*-2.2.27
2.2.28
05/07/2024
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 – Authenticated (Contributor+) File inclusion via Shortcode
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the reservation_extra_field shortcode parameter. This makes it…
*-2.2.25
2.2.26
24/06/2024
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 – Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode
The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all versions up to, and including, 2.2.24 due to…
*-2.2.24
2.2.26
30/05/2024
WPCafe <= 2.2.23 – Unauthenticated Blind Server-Side Request Forgery
The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes…
*-2.2.23
2.2.24
22/05/2024
WPCafe <= 2.2.22 – Missing Authorization
The WPCafe plugin for WordPress is vulnerable to unauthorized access, modification, or loss of data due to a missing capability check on several functions in versions up to, and including, 2.2.22. This makes it possible for unauthenticated attackers…
*-2.2.22
2.2.23
15/11/2023
WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation <= 2.1.4 – Cross-Site Scripting
The WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including 2.1.4 due to insufficient input sanitization and output escaping on…
*-2.1.4
2.2.0
06/08/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.