Themewinter
Themewinter Wpcafe: vulnerabilidades y CVE
Themewinter Wpcafe tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86812 | Media (6.5) | 0.27% | — | 11 sept 2026 | The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated… |
| CVE-2026-14550 | Media (5.3) | 0.25% | — | 26 ago 2026 | The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit… |
| CVE-2026-11818 | Media (5.4) | 0.41% | — | 10 jul 2026 | The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly… |
| CVE-2026-57622 | Media (4.3) | 0.27% | — | 26 jun 2026 | Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. |
| CVE-2023-47805 | Crítica (9.8) | 0.50% | — | 9 dic 2024 | Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCafe: from n/a through <= 2.2.22. |
| CVE-2024-43135 | Alta (8.8) | 0.53% | — | 13 ago 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28. |
| CVE-2024-37513 | Alta (8.8) | 0.56% | — | 9 jul 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows Path Traversal.This issue affects WPCafe: from n/a through 2.2.27. |
| CVE-2024-5431 | Alta (8.8) | 0.59% | — | 25 jun 2024 | The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.25 via the… |
| CVE-2024-5427 | Media (5.4) | 0.32% | — | 31 may 2024 | The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Reservation Form shortcode in all… |
| CVE-2024-1855 | Media (5.3) | 0.44% | — | 23 may 2024 | The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via… |