SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-66586

MEDIUM · CVSS 6.6 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

WP Cafe Pro versions prior to 3.0.15 are vulnerable to a Local File Inclusion (LFI) attack, allowing authenticated users to access sensitive files on the server. This could lead to unauthorized information disclosure, potentially compromising the integrity of the application. Organizations using affected versions should prioritize patching to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-66586
Severity
MEDIUM
CVSS
6.6
EPSS
0.33%

Original NVD Description

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.