Insecure Direct Object Reference in Quick Restaurant Menu Plugin for WordPress
CVE-2023-0550
4.3MEDIUM
Summary
The Quick Restaurant Menu plugin for WordPress suffers from an Insecure Direct Object Reference vulnerability in versions up to 2.0.2. This issue occurs because the plugin fails to validate the post ID provided to the AJAX action during menu item deletion or modification. As a result, authenticated users with subscriber-level access or higher can potentially modify or delete any post, regardless of ownership, thus compromising the integrity of the website.
Affected Version(s)
Quick Restaurant Menu * <= 2.0.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka