CVE-2026-75028: WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
- Severity
- 7.5 (HIGH)
- Vendor
- ARRAYTICS
- Affected versions
- 0 through 3.0.18
- Patch status
- Unknown
- Published
- 2026-10-03T07:16:48.160
- Modified
- 2026-10-03T16:16:38.153
Why it matters
This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.
Recommended admin actions
- Review and patch based on exposure, asset criticality, and business impact.
- Check whether the affected WordPress plugin or theme is installed.
- Update, disable, or remove the affected component if present.
Technical summary
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
View the official NVD record for CVE-2026-75028
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-105105 |
AIT-Core
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-105080 |
Product identification pending PATCH
Reporter: CVE
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-71885 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-87115 |
VikAppointments Services Booking Calendar
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-92084 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
9.1
CRITICAL
|
VIEW RECORD |
| CVE-2026-92536 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-97644 |
Groundhogg — CRM, Newsletters, and Marketing Automation
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-88783 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-18443 |
Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-105115 |
OpenAM PATCH
Reporter: DISCLOSURE
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-96451 |
Ultimate Member PATCH
Reporter: AUDIT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-104433 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71888 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71889 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-71890 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-89236 |
SaveTo Wishlist Lite PATCH
Reporter: CONTACT
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-104476 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-91078 |
TillKit PATCH
Reporter: CONTACT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71883 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71886 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-71887 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-85515 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-103065 |
Kirki PATCH
Reporter: AUDIT
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-101923 |
Photo Reviews for WooCommerce
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-94505 |
Nelio Content – Editorial Calendar & Social Media Auto-Posting
Reporter: SECURITY
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-105119 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-93428 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101159 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101160 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-101161 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103514 |
WP 2FA PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-103913 |
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-97337 |
Simple Membership
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-75028 |
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96267 |
WP Visitor Statistics (Real Time Traffic)
Reporter: SECURITY
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-96270 |
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-92977 |
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-101928 |
Magic Tooltips For Contact Form 7
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-87091 |
Welcart e-Commerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93430 |
GD Rating System
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96564 |
SEOPress – AI SEO Plugin & On-site SEO
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96575 |
Transliterator – Multilingual and Multi-script Text Conversion
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-96650 |
Strong Testimonials
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97341 |
Visitor Traffic Real Time Statistics
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-93889 |
Mail logging & Catcher
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-97660 |
WPC Product Options for WooCommerce
Reporter: SECURITY
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-104478 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-71891 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105113 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-103342 |
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-105030 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-71892 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105120 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-105121 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-103293 |
MPG PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85568 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-88782 |
Kubio AI Page Builder PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94238 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94239 |
Loco Translate PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-85015 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-94539 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-95865 |
Beaver Builder Page Builder – Drag and Drop Website Builder
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100152 |
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-100157 |
WP Ultimate Review
Reporter: SECURITY
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94378 |
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92727 |
EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2025-12828 |
Ultra Addons Lite for Elementor
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-100148 |
Rich Showcase for Google Reviews
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-101162 |
WP Ultimate Review PATCH
Reporter: CONTACT
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-97344 |
Wp Social Login and Register Social Counter
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-15795 |
Responsive Starter Templates – Elementor Templates & Starter Sites
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92767 |
Twenty20 Image Before-After
Reporter: SECURITY
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-92923 |
Unlimited Elements for Elementor PATCH
Reporter: CONTACT
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92243 |
Ivory Search – WordPress Search Plugin
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92538 |
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92551 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92826 |
EWWW Image Optimizer
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-103888 |
WPC Smart Quick View for WooCommerce
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-103909 |
Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-104313 |
WPC Estimated Delivery Date for WooCommerce
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92974 |
Photo Gallery by 10Web – Mobile-Friendly Image Gallery
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93896 |
WPFront Notification Bar
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-105112 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6
MEDIUM
|
VIEW RECORD |
| CVE-2026-18040 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-104474 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-100180 |
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-103421 |
WPMobile.App – Android and iOS App Builder
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-103519 |
WP Ultimate Review
Reporter: SECURITY
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-104477 |
Product identification pending
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105029 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-100149 |
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86832 |
MetForm PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92437 |
Mailchimp for WooCommerce PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-11601 |
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System
Reporter: SECURITY
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-97873 |
Product identification pending PATCH
Reporter: 91579145-5D7B-4CC5-B925-A0262FF19630
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105114 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105117 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-105122 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-104475 |
Product identification pending
Reporter: DISCLOSURE
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-104479 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
5.1
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.