CVE · Medium

CVE-2023-37985 — Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-37985 Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.7 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.4.7 2.4.7 2023-07-17

CVE-2023-37985

The Restaurant Menu and Food Ordering by Five Star Plugins plugin for WordPress through version 2.4.6 contains a Cross-Site Request Forgery vulnerability in the 'maybe_duplicate_item' function due to inadequate nonce verification. An unauthenticated attacker could exploit this to create duplicate menu items by crafting a malicious request, provided they can persuade a site administrator to interact with the attack link. The vulnerability was fixed in version 2.4.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.