Five Star Restaurant Menu and Food Ordering <= 2.5.2 - Missing Authorization
medium
The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.5.2
- Fixed in:
- 2.5.3
- Disclosed:
- Jun 18, 2026
CVE-2026-54835 on NVD →
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.17
unknown
[en] The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers,...
- Affected:
- up to 2.4.17
- Fixed in:
- 2.4.17
- Disclosed:
- Jun 5, 2024
CVE-2024-5459 on NVD →
Restaurant Menu and Food Ordering <= 2.4.16 - Missing Authorization to Menu Creation
medium
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 2.4.16
- Fixed in:
- 2.4.17
- Disclosed:
- Jun 4, 2024
CVE-2024-5459 on NVD →
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.15
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14.
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- Mar 19, 2024
CVE-2024-29089 on NVD →
Five Star Restaurant Menu <= 2.4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Five Star Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web script...
- CVSS:
- 6.4
- Affected:
- up to 2.4.14
- Fixed in:
- 2.4.15
- Disclosed:
- Mar 15, 2024
CVE-2024-29089 on NVD →
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.11
unknown
[en] The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.
- Affected:
- up to 2.4.11
- Fixed in:
- 2.4.11
- Disclosed:
- Nov 20, 2023
CVE-2023-5340 on NVD →
Five Star Restaurant Menu and Food Ordering <= 2.4.10 - Unauthenticated PHP Object Injection
critical
The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.10 via deserialization of untrusted input from the 'options' parameter supplied via the 'fdm_update_cart_item' AJAX action. This makes it possible for unauthenticated atta...
- CVSS:
- 9.8
- Affected:
- up to 2.4.10
- Fixed in:
- 2.4.11
- Disclosed:
- Oct 27, 2023
CVE-2023-5340 on NVD →
Restaurant Menu and Food Ordering by Five Star Plugins <= 2.4.6 - Cross-Site Request Forgery via maybe_duplicate_item
medium
The Restaurant Menu and Food Ordering by Five Star Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the 'maybe_duplicate_item' function. This makes it possible for unauthenticated attackers to duplic...
- CVSS:
- 4.3
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Jul 17, 2023
CVE-2023-37985 on NVD →
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
- Disclosed:
- Jul 17, 2023
CVE-2023-37985 on NVD →
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.2.1
unknown
[en] The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Mar 11, 2021
CVE-2020-29045 on NVD →
Five Star Restaurant Menu <= 2.2.0 - Unauthenticated Arbitrary Object Deserialization leading to Remote Code Execution
critical
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
- CVSS:
- 9.8
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jan 11, 2021
CVE-2020-29045 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database