CVE Database /
CVE-2020-29045
CVE · Critical
CVE-2020-29045 — Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-29045
|
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.2.1 |
Deserialization of Untrusted Data |
Critical
9.8
|
< 2.2.1
|
2.2.1 |
2021-01-11 |
—
|
CVE-2020-29045
The food-and-drink-menu plugin versions before 2.2.1 contains a code execution vulnerability in its cart management functionality. An attacker can exploit an unsafe unserialize operation performed on the fdm_cart cookie within the load_cart_from_cookie function to execute arbitrary code on affected WordPress installations. This flaw allows remote attackers to compromise the security of websites running vulnerable versions of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings