CVE-2026-84044: Restaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPN
Published Sep 4, 2026
·Updated
The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment.
Affected Software
1 affected component
WordPress Restaurant Menu and Food Ordering<2.4.12
Event History
Sep 4, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote attacker can exploit it. The attacker can forge a PayPal payment notification for an order they control, without making a payment.
2
What is the practical impact on an affected site?
An attacker can cause their own order to be marked paid and completed. This can result in fulfillment of food orders that were never actually paid for.
3
How can I tell whether my site is affected?
Sites using the WordPress Restaurant Menu and Food Ordering plugin with a version earlier than 2.4.12 are affected.