PLUGIN SECURITY
Is Wp Cafe safe?
Restaurant management solution for restaurant menus, online food ordering, delivery, pickup, QR ordering, and table reservations with WooCommerce.
What this plugin does
- Slug:
wp-cafe - Author: Arraytics
- 5000+ active installs
- 92/100 rating (108 reviews on wordpress.org)
- 296023 all-time downloads
- On WordPress.org since 2020-05-21
bookingFood Deliveryfood menureservationrestaurant
Maintenance status
- Latest known version: 3.0.17
- Last updated: 2026-08-16 2:38pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): <8.0
Known vulnerabilities
11 known CVEs on file for Wp Cafe. Reported between 2022 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-57622 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.15 | Missing Authorization | Medium 4.3 | < 3.0.15 | 3.0.15 | 2026-06-25 | ✓ fixed in latest |
| CVE-2026-11818 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.15 | Missing Authorization | Medium 5.4 | < 3.0.15 | 3.0.15 | 2026-06-25 | ✓ fixed in latest |
| CVE-2026-27071 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.8 | Missing Authorization | Critical 9.1 | < 3.0.8 | 3.0.8 | 2026-03-12 | ✓ fixed in latest |
| CVE-2025-39452 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.33 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 2.2.33 | 2.2.33 | 2025-04-17 | ✓ fixed in latest |
| CVE-2025-30829 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.32 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 2.2.32 | 2.2.32 | 2025-03-27 | ✓ fixed in latest |
| CVE-2024-43135 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.29 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 2.2.29 | 2.2.29 | 2024-08-07 | ✓ fixed in latest |
| CVE-2024-37513 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.28 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 8.8 | < 2.2.28 | 2.2.28 | 2024-07-05 | ✓ fixed in latest |
| CVE-2024-5431 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.26 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 8.8 | < 2.2.26 | 2.2.26 | 2024-06-24 | ✓ fixed in latest |
+ 4 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-5427 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.26 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.26 | 2.2.26 | 2024-05-30 | ✓ fixed in latest |
| CVE-2024-1855 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.24 | Server-Side Request Forgery (SSRF) | Medium 5.3 | < 2.2.24 | 2.2.24 | 2024-05-22 | ✓ fixed in latest |
| CVE-2023-47805 | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.23 | Missing Authorization | Medium 5.3 | < 2.2.23 | 2.2.23 | 2023-11-15 | ✓ fixed in latest |
| — | WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.0 | — | Unknown | < 2.2.0 | 2.2.0 | 2022-08-06 | ✓ fixed in latest |
How to fix it
Keep Wp Cafe updated — 3.0.17 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress — 100000+ active installs — 98/100 (99) — max PHP 8.4
- Booking for Appointments and Events Calendar – Amelia — 90000+ active installs — 92/100 (785)
- Online Scheduling and Appointment Booking System – Bookly — 60000+ active installs — 88/100 (575) — max PHP <8.0
- Simply Schedule Appointments — 50000+ active installs — 100/100 (155) — max PHP 8.4
- SimplyBook.me – Booking and reservations calendar — 30000+ active installs — 90/100 (17) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.