Extension WordPress
Vulnérabilités Restaurant Menu and Food Ordering
Cette page rassemble les failles publiées pour Restaurant Menu and Food Ordering, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Restaurant Menu and Food Ordering
6 fiches
Restaurant Menu and Food Ordering <= 2.4.10 – Authenticated (Contributor+) SQL Injection
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-2.4.10
2.4.11
26/06/2026
Restaurant Menu and Food Ordering <= 2.4.11 – Missing Authorization
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.4.11. This makes it possible for authenticated attackers, with…
*-2.4.11
Non indiqué
26/06/2026
Restaurant Menu by MotoPress <= 2.4.7 – Authenticated (Subscriber+) Information Exposure
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive…
*-2.4.7
2.4.8
09/11/2025
Restaurant Menu by MotoPress <= 2.4.6 – Cross-Site Request Forgery
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.6. This is due to missing or incorrect nonce validation on a function. This makes it…
*-2.4.6
2.4.7
16/07/2025
Restaurant Menu by MotoPress <= 2.4.4 – Authenticated (Contributor+) Local File Inclusion
The Restaurant Menu by MotoPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary…
*-2.4.4
2.4.5
27/03/2025
Restaurant Menu by MotoPress <= 2.4.1 – Admin+ Stored Cross Site Scripting
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is…
[*, 2.4.2)
2.4.2
28/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.