plugin

Simple Retail Menus Vulnerabilities

6 known security issues reported for the Simple Retail Menus WordPress plugin. Most recent disclosed Feb 20, 2026.

2 high

Running Simple Retail Menus on your site? Check whether your installed version is affected.

Scan your site free

Simple Retail Menus [simple-retail-menus] <= 4.2.1 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1.

Affected:
up to 4.2.1
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-69387 on NVD →

Simple Retail Menus <= 4.2.1 - Unauthenticated Local File Inclusion

high

The Simple Retail Menus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access...

CVSS:
8.1
Affected:
up to 4.2.1
Fix:
No patched version reported
Disclosed:
Feb 9, 2026

CVE-2025-69387 on NVD →

Simple Retail Menus <= 4.0.1 - SQL Injection

high

SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1 for WordPress allows remote authenticated editors to execute arbitrary SQL commands via the targetmenu parameter in an edit action to wp-admin/admin.php.

CVSS:
8.8
Affected:
up to 4.0.1
Fixed in:
4.1
Disclosed:
May 28, 2015

CVE-2014-5183 on NVD →

Simple Retail Menus [simple-retail-menus] < 4.1

unknown

[en] SQL injection vulnerability in includes/mode-edit.php in the Simple Retail Menus (simple-retail-menus) plugin before 4.1 for WordPress allows remote authenticated editors to execute arbitrary SQL commands via the targetmenu parameter in an edit action to wp-admin/admin.php.

Affected:
up to 4.1
Fixed in:
4.1
Disclosed:
Aug 6, 2014

CVE-2014-5183 on NVD →

Simple Retail Menus [simple-retail-menus] < 4.1

unknown

This plugin is prone to an SQL injection in includes/actions.php targetmenu parameter . Update the plugin.

Affected:
up to 4.1
Fixed in:
4.1
Disclosed:
Aug 1, 2014

Simple Retail Menus [simple-retail-menus] < 4.1

unknown

The Simple Retail Menus WordPress plugin was affected by an includes/actions.php targetmenu Parameter SQL Injection security vulnerability.

Affected:
up to 4.1
Fixed in:
4.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database