CVE-2026-66586

Summary

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Affected Software

VendorProductVersion RangeStatus
ThemewinterWP Cafe Pron/a < 3.0.15affected

Weaknesses

  • CWE-98: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References