Restaurant Cafeteria <= 0.4.6 - Missing Authorization to (Subscriber+) Arbitrary Plugin Installation/Activation
highThe Restaurant Cafeteria theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'restaurant_cafeteria_install_and_activate_plugin' AJAX action in all versions up to, and including, 0.4.6. This makes it possible for authenticated attackers, with subscriber-level access and abov...
- CVSS:
- 8.8
- Affected:
- up to 0.4.6
- Fix:
- No patched version reported
- Disclosed:
- Mar 6, 2026