CVE · High

CVE-2026-0974 — Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-0974 Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1 Missing Authorization High 8.8 < 1.20.1 1.20.1 2026-02-18

CVE-2026-0974

The Orderable plugin for WordPress lacks a crucial permission check in its installation process, allowing users with minimal privileges or higher to secretly add any plugin they choose, potentially unleashing malicious code on vulnerable sites. This oversight affects all versions of the plugin up to and including 1.20.0. As a result, attackers can exploit this weakness to execute arbitrary code remotely.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.