Input validation vulnerability in RestroPress – Online Food Ordering System 2.8.2

The RestroPress plugin for WordPress has a security flaw in versions up to and including 2.8.2. This flaw makes it possible for an unauthenticated attacker to modify the contents of other users’ shopping carts. This could happen if an attacker can trick a site administrator into clicking on a malicious link. To protect against this, nonce validation needs to be added to various AJAX actions.

Detected in:

RestroPress – Online Food Ordering System open vulnerable versions: >= * <= 2.8.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.