Unauthorized Access Vulnerability in Food Menu Plugin for WooCommerce
CVE-2024-13415
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 January 2025
What is CVE-2024-13415?
The Food Menu β Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress contains a vulnerability due to a missing capability check in the response() function. This issue affects all versions up to and including 5.1.4, allowing authenticated users with Subscriber-level access and above to potentially modify plugin settings. Exploiting this vulnerability may lead to unauthorized configuration changes, emphasizing the importance of timely updates and robust security practices.
Affected Version(s)
Food Menu β Restaurant Menu & Online Ordering for WooCommerce 0 <= 5.1.4