CVE · Critical

CVE-2020-29045 — Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-29045 Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.2.1 Deserialization of Untrusted Data Critical 9.8 < 2.2.1 2.2.1 2021-01-11

CVE-2020-29045

The food-and-drink-menu plugin versions before 2.2.1 contains a code execution vulnerability in its cart management functionality. An attacker can exploit an unsafe unserialize operation performed on the fdm_cart cookie within the load_cart_from_cookie function to execute arbitrary code on affected WordPress installations. This flaw allows remote attackers to compromise the security of websites running vulnerable versions of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.