天下漏洞,尽知其名
HIGH

CVE-2026-75028 WPCafe WordPress 插件本地文件包含漏洞

影响具有贡献者权限的攻击者可包含并执行任意 PHP 文件,导致代码执行或敏感数据泄露

AI 研判

WPCafe 是 WordPress 的一款餐厅菜单、在线订餐与餐桌预订插件。该插件在 3.0.18 及之前所有版本中,其 template scope 函数存在本地文件包含漏洞。攻击者可借此包含并执行服务器上的任意 .php 文件。

影响范围

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System

受影响版本为 WPCafe 插件 3.0.18 及之前的所有版本,暂无公开信息说明更高版本是否已修复。

漏洞详情

漏洞类型为本地文件包含(LFI),成因是 template scope 函数未对用户可控的模板路径参数进行充分校验与过滤。具有贡献者(Contributor)及以上权限的认证用户可构造恶意请求,使插件包含服务器本地任意文件。若被包含的文件为 .php 类型,其中的 PHP 代码将被执行,从而实现代码执行、绕过访问控制或读取敏感数据。

利用条件与风险

利用前提是攻击者需具备贡献者及以上权限的认证账户,且服务器上存在可被包含的恶意或可利用 PHP 文件。实战中可导致敏感信息泄露乃至远程代码执行,风险较高。

修复建议

建议升级 WPCafe 插件至官方发布的最新修复版本;若暂无可用补丁,可临时禁用或移除该插件,并严格限制贡献者等低权限账户的创建与权限分配。

原始情报

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.