CVE-2026-66586: WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
Published Aug 20, 2026
·Updated
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Affected Software
1 affected component
WordPress WP Cafe Pro<3.0.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Cafe Pro pluginto a version that resolves this vulnerability.Fixed in 3.0.15
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges. It is not exploitable by an unauthenticated or low-privileged attacker according to the provided vector.
2
Are default WordPress installations affected?
Only WordPress sites using the WP Cafe Pro plugin are in scope. The provided data does not establish whether any particular plugin configuration enables or prevents exploitation.
3
What versions should be remediated?
WP Cafe Pro versions earlier than 3.0.15 are affected. Update the plugin to version 3.0.15 or later.