CVE · Medium

CVE-2024-1855 — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.24

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1855 WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.24 Server-Side Request Forgery (SSRF) Medium 5.3 < 2.2.24 2.2.24 2024-05-22

CVE-2024-1855

The WPCafe restaurant management plugin versions 2.2.23 and earlier contain a server-side request forgery vulnerability in the wpc_check_for_submission function that allows unauthenticated attackers to send arbitrary web requests from the affected server. This flaw enables attackers to initiate connections to any target location using the web application as an intermediary. The vulnerability was resolved in version 2.2.24.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.