CyberRota Analysis
AI-GeneratedWP Cafe Pro versions prior to 3.0.15 are vulnerable to a Local File Inclusion (LFI) attack, allowing authenticated users to access sensitive files on the server. This could lead to unauthorized information disclosure, potentially compromising the integrity of the application. Organizations using affected versions should prioritize patching to mitigate the risk associated with this vulnerability.
CVE
CVE-2026-66586
Severity
MEDIUM
CVSS
6.6
EPSS
0.33%
Original NVD Description
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.