CVE-2024-5459: Restaurant Menu and Food Ordering <= 2.4.16 - Missing Authorization to Menu Creation
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'addsection', 'addmenu', 'addmenuitem', and 'addmenupage' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create menu sections, menus, food items, and new menu pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/restaurant-menu-and-food-orderingto a version that resolves this vulnerability.Fixed in 2.4.16
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5459?
CVE-2024-5459 has a medium severity rating due to the potential for unauthorized data creation.
How do I fix CVE-2024-5459?
To fix CVE-2024-5459, update the Restaurant Menu and Food Ordering plugin to version 2.4.17 or later.
Which versions are affected by CVE-2024-5459?
CVE-2024-5459 affects all versions of the Restaurant Menu and Food Ordering plugin up to and including version 2.4.16.
What functions are vulnerable in CVE-2024-5459?
CVE-2024-5459 specifically affects the 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions.
Can CVE-2024-5459 be exploited remotely?
Yes, CVE-2024-5459 can be exploited remotely due to the lack of necessary capability checks.