CVE-2026-66587

Summary

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Affected Software

VendorProductVersion RangeStatus
WPCafeWP Cafe Pron/a < 3.0.15affected

Weaknesses

  • CWE-98: CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References