Best Restaurant Menu by PriceListo <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary we...
- CVSS:
- 6.4
- Affected:
- up to 1.4.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58812 on NVD →
Great Restaurant Menu WP [best-restaurant-menu-by-pricelisto] <= 1.4.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows Stored XSS. This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.3.
- Affected:
- up to 1.4.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 5, 2025
CVE-2025-58812 on NVD →
Great Restaurant Menu WP [best-restaurant-menu-by-pricelisto] < 1.4.3 (closed)
unknown
[en] Missing Authorization vulnerability in PriceListo Best Restaurant Menu by PriceListo.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.2.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Dec 31, 2024
CVE-2024-49698 on NVD →
Best Restaurant Menu by PriceListo <= 1.4.2 - Missing Authorization
medium
The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a few functions like 'delete_group' in versions up to, and including, 1.4.2. This makes it possible for authenticated attackers, with contributor-level access and above, to perform actio...
- CVSS:
- 4.3
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Oct 21, 2024
CVE-2024-49698 on NVD →
Great Restaurant Menu WP [best-restaurant-menu-by-pricelisto] < 1.4.2 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1.
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Aug 29, 2024
CVE-2024-38793 on NVD →
Best Restaurant Menu by PriceListo <= 1.4.1 - Authenticated (Contributor+) SQL Injection
high
The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contribut...
- CVSS:
- 8.8
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.2
- Disclosed:
- Jul 22, 2024
CVE-2024-38793 on NVD →
Great Restaurant Menu WP [best-restaurant-menu-by-pricelisto] < 1.4.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PriceListo Best Restaurant Menu by PriceListo.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.3.1.
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.0
- Disclosed:
- Nov 18, 2023
CVE-2023-47649 on NVD →
Best Restaurant Menu by PriceListo <= 1.3.1 - Cross-Site Request Forgery via menu_page
medium
The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the menu_page function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forg...
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.4.0
- Disclosed:
- Nov 7, 2023
CVE-2023-47649 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database