plugin

Menu Ordering Reservations Vulnerabilities

17 known security issues reported for the Menu Ordering Reservations WordPress plugin. Most recent disclosed Nov 20, 2024.

1 high 6 medium

Running Menu Ordering Reservations on your site? Check whether your installed version is affected.

Scan your site free

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.4.3

unknown

[en] The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Nov 20, 2024

CVE-2024-9653 on NVD →

Restaurant Menu – Food Ordering System – Table Reservation <= 2.4.2 - Reflected Cross-Site Scripting

medium

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

CVSS:
6.1
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Nov 19, 2024

CVE-2024-9653 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.4.1

unknown

[en] The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Jun 15, 2024

CVE-2024-1399 on NVD →

Restaurant Menu and Food Ordering <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

CVSS:
6.4
Affected:
up to 2.4.0
Fixed in:
2.4.1
Disclosed:
Jun 14, 2024

CVE-2024-1399 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.4.2

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation allows Stored XSS.This issue affects Restaurant Menu – Food Ordering System – Table Reservation: from n/a through 2.4.1.

Affected:
up to 2.4.2
Fixed in:
2.4.2
Disclosed:
Apr 18, 2024

CVE-2024-32579 on NVD →

Restaurant Menu – Food Ordering System – Table Reservation <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for au...

CVSS:
6.4
Affected:
up to 2.4.1
Fixed in:
2.4.2
Disclosed:
Apr 16, 2024

CVE-2024-32579 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.7

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 versions.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Aug 24, 2023

CVE-2023-32516 on NVD →

Menu - Ordering - Reservations <= 2.3.6 - Reflected Cross-Site Scripting via 'redirect'

medium

The Menu - Ordering - Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘redirect’ parameter in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
May 9, 2023

CVE-2023-32516 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.7

unknown

The Menu - Ordering - Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘redirect’ parameter in versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
May 9, 2023

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.6

unknown

[en] The Restaurant Menu WordPress plugin before 2.3.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Feb 6, 2023

CVE-2022-4657 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.6

unknown

Update the WordPress Restaurant Menu – Food Ordering System – Table Reservation plugin to the latest available version (at least 2.3.6). WordfenceTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Restaurant Menu – Food Ordering System – Table Reservation Plugin. This could allow a...

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Jan 5, 2023

Restaurant Menu – Food Ordering System – Table Reservation <= 2.3.5 - Authenticated (Contributor+) Cross-Site Scripting

medium

The Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and...

CVSS:
6.4
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
Jan 4, 2023

CVE-2022-4657 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.6

unknown

The Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and...

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Jan 4, 2023

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.2

unknown

[en] The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal pe...

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Nov 3, 2022

CVE-2022-2696 on NVD →

Restaurant Menu &#8211; Food Ordering System &#8211; Table Reservation [menu-ordering-reservations] < 2.3.2

unknown

[en] The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_optio...

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Nov 3, 2022

CVE-2022-3776 on NVD →

Restaurant Menu – Food Ordering System – Table Reservation <= 2.3.1 - Cross-Site Request Forgery

high

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options to...

CVSS:
8.8
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Oct 31, 2022

CVE-2022-3776 on NVD →

Restaurant Menu – Food Ordering System – Table Reservation <= 2.3.0 - Missing Authorization on AJAX Actions

medium

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permiss...

CVSS:
6.3
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Oct 31, 2022

CVE-2022-2696 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database