CVE-2023-37985: WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Five Star Restaurant Menu Plugin (FiveStarPlugins Restaurant Menu and Food Ordering)to a version that resolves this vulnerability.Fixed in 2.4.7
Event History
Frequently Asked Questions
What is CVE-2023-37985?
CVE-2023-37985 refers to a Cross-Site Request Forgery (CSRF) vulnerability found in the FiveStarPlugins Restaurant Menu and Food Ordering plugin version 2.4.6 and below.
What is the severity of CVE-2023-37985?
CVE-2023-37985 has a severity score of 8.8, which is considered high.
How does CVE-2023-37985 affect the FiveStarPlugins Restaurant Menu and Food Ordering plugin?
CVE-2023-37985 affects the FiveStarPlugins Restaurant Menu and Food Ordering plugin version 2.4.6 and below, allowing for potential Cross-Site Request Forgery (CSRF) attacks.
Is there a patch or fix available for CVE-2023-37985?
Yes, a patch or fix is available for CVE-2023-37985. It is recommended to update to version 2.4.7 or above of the FiveStarPlugins Restaurant Menu and Food Ordering plugin to address the vulnerability.
Where can I find more information about CVE-2023-37985?
You can find more information about CVE-2023-37985 at the following reference link: [https://patchstack.com/database/vulnerability/food-and-drink-menu/wordpress-restaurant-menu-and-food-ordering-by-five-star-plugins-plugin-2-4-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/food-and-drink-menu/wordpress-restaurant-menu-and-food-ordering-by-five-star-plugins-plugin-2-4-6-cross-site-request-forgery-csrf-vulnerability?_s_id=cve)