CVE-2024-13415

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 862

Summary

CVE-2024-13415 is a vulnerability affecting the Food Menu – Restaurant Menu & Online Ordering plugin for WordPress, up to and including version 5.1.4. This issue allows authenticated attackers with Subscriber-level access or higher to gain unauthorized access to the plugin's settings. The cause of this vulnerability is a missing capability check on the response() function within the plugin. Successful exploitation may result in modification of the plugin's settings, potentially leading to significant functionality changes or other unintended consequences. It is strongly recommended that users upgrade to the latest version of the plugin, 5.1.5 or higher, to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share