CVE · Medium

CVE-2024-29089 — Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.15

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-29089 Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.4.15 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.4.15 2.4.15 2024-03-15

CVE-2024-29089

The Five Star Restaurant Menu and Food Ordering plugin for WordPress contains a Cross Site Scripting vulnerability in versions prior to 2.4.15 that allows attackers to inject arbitrary scripts and HTML content into the website. When visitors access the affected site, these malicious injections execute in their browsers, potentially causing redirects, displaying unwanted advertisements, or performing other harmful actions. The flaw was identified by Steven Julian and has been patched in version 2.4.15 and later. Users should upgrade to the fixed version immediately to eliminate this vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.