Simple Retail Menus [simple-retail-menus] <= 4.2.1 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1.
- Affected:
- up to 4.2.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-69387 on NVD →
Simple Retail Menus <= 4.2.1 - Unauthenticated Local File Inclusion
high
The Simple Retail Menus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access...
- CVSS:
- 8.1
- Affected:
- up to 4.2.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 9, 2026
CVE-2025-69387 on NVD →
Simple Retail Menus <= 4.0.1 - SQL Injection
high
SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1 for WordPress allows remote authenticated editors to execute arbitrary SQL commands via the targetmenu parameter in an edit action to wp-admin/admin.php.
- CVSS:
- 8.8
- Affected:
- up to 4.0.1
- Fixed in:
- 4.1
- Disclosed:
- May 28, 2015
CVE-2014-5183 on NVD →
Simple Retail Menus [simple-retail-menus] < 4.1
unknown
[en] SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1 for WordPress allows remote authenticated editors to execute arbitrary SQL commands via the targetmenu parameter in an edit action to wp-admin/admin.php.
- Affected:
- up to 4.1
- Fixed in:
- 4.1
- Disclosed:
- Aug 6, 2014
CVE-2014-5183 on NVD →
Simple Retail Menus [simple-retail-menus] < 4.1
unknown
This plugin is prone to an SQL injection in includes/actions.php targetmenu parameter .
Update the plugin.
- Affected:
- up to 4.1
- Fixed in:
- 4.1
- Disclosed:
- Aug 1, 2014
Simple Retail Menus [simple-retail-menus] < 4.1
unknown
The Simple Retail Menus WordPress plugin was affected by an includes/actions.php targetmenu Parameter SQL Injection security vulnerability.
- Affected:
- up to 4.1
- Fixed in:
- 4.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database