Unauthorized Access Vulnerability in Food Menu Plugin for WooCommerce
CVE-2024-13415

4.3MEDIUM

What is CVE-2024-13415?

The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress contains a vulnerability due to a missing capability check in the response() function. This issue affects all versions up to and including 5.1.4, allowing authenticated users with Subscriber-level access and above to potentially modify plugin settings. Exploiting this vulnerability may lead to unauthorized configuration changes, emphasizing the importance of timely updates and robust security practices.

Affected Version(s)

Food Menu – Restaurant Menu & Online Ordering for WooCommerce 0 <= 5.1.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

abrahack
.