SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66587

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

WP Cafe Pro versions prior to 3.0.15 are vulnerable to an unauthenticated Local File Inclusion (LFI) flaw, allowing attackers to access sensitive files on the server. This critical vulnerability, rated 9.8 on the CVSS scale, poses a significant risk of data exposure and potential system compromise. Organizations using affected versions should prioritize immediate patching to mitigate the threat.

CVE
CVE-2026-66587
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%

Original NVD Description

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.