CVE Database /
CVE-2024-43135
CVE · High
CVE-2024-43135 — WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.29
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-43135
|
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.29 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
8.8
|
< 2.2.29
|
2.2.29 |
2024-08-07 |
—
|
CVE-2024-43135
The WPCafe plugin through version 2.2.28 contains a local file inclusion vulnerability affecting certain block components accessible through the template_file parameter. Authenticated users with contributor-level permissions or higher can exploit this flaw to include and execute arbitrary files from the server, potentially running malicious PHP code. The vulnerability enables attackers to circumvent security restrictions, access confidential information, or achieve code execution by uploading benign-appearing files such as images that can then be included and processed as code.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings