CVE-2025-30846: WordPress Restaurant Menu by MotoPress plugin <= 2.4.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows PHP Local File Inclusion.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30846?
CVE-2025-30846 has a high severity rating due to its potential for remote file inclusion vulnerabilities.
How do I fix CVE-2025-30846?
To fix CVE-2025-30846, update the Restaurant Menu by MotoPress plugin to version 2.4.5 or later.
What types of systems are affected by CVE-2025-30846?
CVE-2025-30846 affects the Restaurant Menu by MotoPress and WordPress Restaurant Menu plugins up to version 2.4.4.
What is the impact of CVE-2025-30846 on my website?
The impact of CVE-2025-30846 on your website can lead to unauthorized access to local files which may compromise your sensitive data.
Is CVE-2025-30846 exploitable remotely?
Yes, CVE-2025-30846 is exploitable remotely, allowing attackers to execute malicious scripts on the vulnerable system.