Authorization Bypass Flaw in Quick Restaurant Menu Plugin for WordPress
CVE-2023-0555
What is CVE-2023-0555?
The Quick Restaurant Menu plugin for WordPress is susceptible to an authorization bypass vulnerability due to inadequate capability checks in its AJAX functionality. This flaw allows authenticated users with subscriber-level permissions and above to access privileged actions intended exclusively for administrators, including creating, updating, and deleting menu items. Furthermore, the plugin lacks adequate verification mechanisms for post IDs provided in its AJAX requests, potentially leading to unauthorized deletion or alteration of arbitrary posts. It is essential for users of this plugin to update to the latest version to mitigate these risks and secure their WordPress installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Quick Restaurant Menu * <= 2.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved