The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.18 via the (template scope) function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The WPCafe restaurant management plugin for WordPress contains a Local File Inclusion (LFI) vulnerability in its template handling function that allows authenticated contributors and above to include and execute arbitrary PHP files on the server. With a CVSS score of 7.5, this vulnerability poses a significant risk to WordPress installations running affected versions up to 3.0.18. Any WordPress site using this popular restaurant and food ordering plugin is vulnerable if user roles with contributor-level permissions exist, potentially allowing attackers to execute malicious PHP code, access sensitive database information, modify site content, or establish persistent backdoors for further compromise.
While this CVE doesn't map directly to MITRE ATT&CK techniques, Casky's security skills—powered by Claude AI with extended reasoning capabilities—would detect attack patterns associated with Execution and Defense Evasion techniques. Practitioners using Casky would identify suspicious behaviors including: unusual PHP file inclusions in web server logs, template function calls with file path parameters pointing outside expected directories, post-authentication activity from low-privilege accounts attempting file system access, and execution of unexpected PHP code within the plugin's context. The platform's skill set would correlate these indicators with CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program) patterns, alerting security teams to investigate contributor account activity and review plugin file inclusion logs for evidence of exploitation or reconnaissance activity.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-75028. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation