Extension WordPress
Vulnérabilités Five Star Restaurant Menu and Food Ordering
Cette page rassemble les failles publiées pour Five Star Restaurant Menu and Food Ordering, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Five Star Restaurant Menu and Food Ordering
6 fiches
Five Star Restaurant Menu and Food Ordering <= 2.5.2 – Missing Authorization
The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.2. This makes it possible for unauthenticated…
*-2.5.2
2.5.3
18/06/2026
Restaurant Menu and Food Ordering <= 2.4.16 – Missing Authorization to Menu Creation
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This…
*-2.4.16
2.4.17
04/06/2024
Five Star Restaurant Menu <= 2.4.14 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Five Star Restaurant Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.4.14
2.4.15
15/03/2024
Five Star Restaurant Menu and Food Ordering <= 2.4.10 – Unauthenticated PHP Object Injection
The Five Star Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.10 via deserialization of untrusted input from the 'options' parameter supplied via the 'fdm_update_cart_item'…
*-2.4.10
2.4.11
27/10/2023
Restaurant Menu and Food Ordering by Five Star Plugins <= 2.4.6 – Cross-Site Request Forgery via maybe_duplicate_item
The Restaurant Menu and Food Ordering by Five Star Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on the 'maybe_duplicate_item'…
[*, 2.4.7)
2.4.7
17/07/2023
Five Star Restaurant Menu <= 2.2.0 – Unauthenticated Arbitrary Object Deserialization leading to Remote Code Execution
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
[*, 2.2.1)
2.2.1
11/01/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.