Orderable <= 1.20.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
highThe Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'install_plugin' function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers,...
- CVSS:
- 8.8
- Affected:
- up to 1.20.0
- Fixed in:
- 1.20.1
- Disclosed:
- Feb 18, 2026