Authorization Flaw in PriceListo's Best Restaurant Menu Plugin
CVE-2024-49698
4.3MEDIUM
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 31 December 2024
Summary
A significant authorization vulnerability exists in the Best Restaurant Menu plugin developed by PriceListo. This flaw allows unauthorized access to restricted functionalities, potentially exposing sensitive information and enabling malicious actions. The vulnerability affects all versions up to and including 1.4.2, creating an urgent need for users to assess their security posture and implement appropriate measures to mitigate risks. An update or patch is recommended to ensure the integrity and safety of web applications utilizing this plugin.
Affected Version(s)
Best Restaurant Menu by PriceListo <= 1.4.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc / truonghuuphuc (Patchstack Alliance)