CVE WATCH / VULNERABILITY DETAIL
CVE-2026-75028
HIGHCVSS 7.5NVD feed
Published 3 October 2026 · tracked since 3 October 2026
Description
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and a
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-94505 HIGH 8.1
- CVE-2026-96267 HIGH 7.5
- CVE-2026-87115 CRITICAL 9.1
- CVE-2026-93889 HIGH 7.2
- CVE-2026-18443 HIGH 8.8
- CVE-2026-100157 MEDIUM 6.5
- CVE-2026-97341 HIGH 7.2
- CVE-2026-96650 HIGH 7.2
- CVE-2026-97337 HIGH 7.5
- CVE-2026-96564 HIGH 7.2