CVE-2025-54038: WordPress Restaurant Menu by MotoPress plugin <= 2.4.6 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress allows Cross Site Request Forgery. This issue affects Restaurant Menu by MotoPress: from n/a through 2.4.6.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54038?
CVE-2025-54038 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can potentially lead to unauthorized actions within the affected application.
How do I fix CVE-2025-54038?
To fix CVE-2025-54038, update the Restaurant Menu by MotoPress plugin to version 2.4.7 or later to mitigate the CSRF vulnerability.
Which versions of Restaurant Menu by MotoPress are affected by CVE-2025-54038?
CVE-2025-54038 affects all versions of Restaurant Menu by MotoPress from n/a through 2.4.6.
What type of attacks can exploit CVE-2025-54038?
CVE-2025-54038 can be exploited to perform unauthorized actions on behalf of users without their consent.
Who is impacted by CVE-2025-54038?
Users of Restaurant Menu by MotoPress versions up to 2.4.6 are impacted by CVE-2025-54038 and should take immediate action to secure their installations.