Description
WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin WPCafe-Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce version 2.2.23 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.24 or latest
References
Related Vulnerabilities
WordPress Plugin WP PHP widget Information Disclosure (1.0.2)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0791)
WordPress Plugin FV Flowplayer Video Player Multiple Vulnerabilities (7.3.14.727)
WebLogic CVE-2023-21838 Vulnerability (CVE-2023-21838)
WordPress Plugin Caldera Forms-More Than Contact Forms Cross-Site Scripting (1.4.1)