Input validation vulnerability in Restaurant Menu and Food Ordering by Five Star Plugins 2.4.7

The Restaurant Menu and Food Ordering by Five Star Plugins plugin for WordPress has a security flaw that could allow unauthenticated attackers to duplicate menu items. This vulnerability affects versions up to, and including, 2.4.6 of the plugin. The cause of the vulnerability is that the ‘maybe_duplicate_item’ function does not have proper nonce validation. This means that if a malicious party can trick an administrator into clicking on a link, they can send a forged request and duplicate a menu item.

Detected in:

Five Star Restaurant Menu and Food Ordering fixed vulnerable versions: >= * < 2.4.7
Restaurant Menu and Food Ordering fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.