Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-66587: WordPress WP Cafe Pro < 3.0.15 can expose server files

CVE-2026-66587 · published 10 days ago
Summary

The WP Cafe Pro add‑on for WordPress, in any version older than 3.0.15, lets anyone on the internet view files stored on your web server. This could reveal sensitive information such as passwords, configuration settings, or other private data. Upgrade the plugin to version 3.0.15 or newer, or remove it if you cannot update, and make sure your website is running the latest WordPress core version.

What to do
  • Update wpcafe wp cafe pro to version 3.0.15.
Affected software
VendorProductAffected versions
wpcafe wp cafe pro < 3.0.15
Fix: upgrade to 3.0.15
Original advisory text
WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-98Improper Control of Filename for Include
Timeline
Published24 Aug 2026
Updated30 Aug 2026
First seen24 Aug 2026
Sources
CVE-2026-66587 · MITRE
Monitor software like this
Free during beta