Input validation vulnerability in WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation 2.1.4

The WPCafe plugin for WordPress is vulnerable to a security issue called Cross-Site Scripting. This means attackers can inject malicious code into the website, which can then be executed in visitors’ browsers. The issue exists in versions up to and including 2.1.4, and is caused by a lack of proper input sanitization and output escaping on the wpc_location_id parameter.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.