What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.
Explanation of Vulnerability in Simple Terms
WPCafe versions up to 2.2.28 contain a path traversal vulnerability that allows authenticated attackers to read and write arbitrary files on the server. An attacker with low-level access can bypass directory restrictions and access sensitive files outside the intended application directory. This can lead to exposure of configuration files, database credentials, or modification of critical site files.
What an attacker can do
Read or write arbitrary files on the server outside the intended application directory.
Potential impact on your site
Sensitive files (config, database credentials) may be exposed or modified; site integrity and confidentiality at risk.
Conditions required to exploit
Attacker must have a low-level user account on the site; no user interaction required.
Key dates
External resources
Related vulnerabilities