CVE-2024-29089
The Five Star Restaurant Menu and Food Ordering plugin for WordPress contains a Cross Site Scripting vulnerability in versions prior to 2.4.15 that allows attackers to inject arbitrary scripts and HTML content into the website. When visitors access the affected site, these malicious injections execute in their browsers, potentially causing redirects, displaying unwanted advertisements, or performing other harmful actions. The flaw was identified by Steven Julian and has been patched in version 2.4.15 and later. Users should upgrade to the fixed version immediately to eliminate this vulnerability.
Based on public CVE data (MITRE/NVD).