The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.2.23 via the wpc_check_for_submission function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application.
References
Configurations
History
No history.
Information
Published : 2024-05-23 02:15
Updated : 2025-03-06 15:03
NVD link : CVE-2024-1855
Mitre link : CVE-2024-1855
CVE.ORG link : CVE-2024-1855
JSON object : View
Products Affected
themewinter
- wpcafe
CWE
CWE-918
Server-Side Request Forgery (SSRF)
