CVE-2026-66587: WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Affected Software
1 affected component
WordPress WP Cafe Pro<3.0.15
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Cafe Pro pluginto a version that resolves this vulnerability.Fixed in 3.0.15
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior access to the site.
2
Which installations are affected?
WP Cafe Pro versions earlier than 3.0.15 are affected. The provided information does not identify any configuration prerequisite.
3
What is the potential impact?
The issue is rated critical with a CVSS score of 9.8 and can affect confidentiality, integrity, and availability at high impact levels.
4
What should be done to remediate it?
Update WP Cafe Pro to version 3.0.15 or later.