plugin

Fw Food Menu Vulnerabilities

2 known security issues reported for the Fw Food Menu WordPress plugin. Most recent disclosed Jun 24, 2025.

2 critical

Running Fw Food Menu on your site? Check whether your installed version is affected.

Scan your site free

FW Food Menu <= 6.0.0 - Unauthenticated Arbitrary File Deletion

critical

The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 6.0.0. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, whi...

CVSS:
9.1
Affected:
up to 6.0.0
Fix:
No patched version reported
Disclosed:
Jun 24, 2025

CVE-2025-49448 on NVD →

FW Food Menu <= 6.0.0 - Unauthenticated Arbitrary File Upload

critical

The FW Food Menu – Responsive food menu with ordering & delivery solutions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 6.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's s...

CVSS:
9.8
Affected:
up to 6.0.0
Fix:
No patched version reported
Disclosed:
Jun 12, 2025

CVE-2025-49447 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database