Input validation vulnerability in Five Star Restaurant Menu and Food Ordering 2.4.10

The Five Star Restaurant Menu and Food Ordering plugin is a popular plugin for WordPress websites. Unfortunately, all versions up to and including 2.4.10 have a security vulnerability which could be exploited by an unauthenticated attacker. This vulnerability is called PHP Object Injection and it involves the injection of a malicious code through the ‘options’ parameter supplied via the ‘fdm_update_cart_item’ AJAX action. This malicious code could be used to delete files, access sensitive data or even execute code on the target system, depending on what other plugins or themes are installed.

Detected in:

Five Star Restaurant Menu and Food Ordering fixed vulnerable versions: >= * <= 2.4.10
Restaurant Menu and Food Ordering fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.