What the vulnerability does
01Description
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Explanation of Vulnerability in Simple Terms
WP Cafe Pro before version 3.0.15 contains a PHP remote file inclusion vulnerability that allows high-privileged users to include and execute arbitrary PHP files from external sources. An attacker with administrative access can exploit this to run malicious code on the site. Update to version 3.0.15 or later to patch this issue.
What an attacker can do
Run arbitrary PHP code on the site by including malicious files from external servers.
Potential impact on your site
A compromised admin account can be used to execute arbitrary code and fully compromise the site.
Conditions required to exploit
Attacker must have high-level administrative privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities