CVE Database /
CVE-2026-0974
CVE · High
CVE-2026-0974 — Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-0974
|
Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1 |
Missing Authorization |
High
8.8
|
< 1.20.1
|
1.20.1 |
2026-02-18 |
—
|
CVE-2026-0974
The Orderable plugin for WordPress lacks a crucial permission check in its installation process, allowing users with minimal privileges or higher to secretly add any plugin they choose, potentially unleashing malicious code on vulnerable sites. This oversight affects all versions of the plugin up to and including 1.20.0. As a result, attackers can exploit this weakness to execute arbitrary code remotely.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings