CVE-2020-29045: Critical severity five star plugins five star restaurant menu vulnerability
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdmcart cookie in loadcartfromcookie in includes/class-cart-manager.php.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the food-and-drink-menu plugin in WordPress?
The vulnerability ID for the food-and-drink-menu plugin in WordPress is CVE-2020-29045.
What is the severity of CVE-2020-29045?
CVE-2020-29045 has a severity rating of 9.8, which is considered critical.
How does CVE-2020-29045 allow remote attackers to execute arbitrary code?
CVE-2020-29045 allows remote attackers to execute arbitrary code through an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
What is the affected software version for CVE-2020-29045?
The affected software version for CVE-2020-29045 is the food-and-drink-menu plugin through version 2.2.0 for WordPress.
How can I fix the CVE-2020-29045 vulnerability?
To fix the CVE-2020-29045 vulnerability, update the food-and-drink-menu plugin to version 2.3.0 or higher.