VendorsFive Star Pluginsfive_star_restaurant_menuany version
Vulnerabilities

Five Star Plugins Five Star Restaurant Menu any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-29045
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.
Published 2021-03-11 · Modified
9.8EPSS 0.308
CVE-2023-5340
Five Star Restaurant Menu and Food Ordering < 2.4.11 - Unauthenticated PHP Object Injection
Published 2023-11-20 · Modified
9.8EPSS 0.012
CVE-2023-37985
WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-07-17 · Modified
8.8EPSS 0.003
CVE-2023-34017
WordPress Five Star Restaurant Reservations Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)
Published 2023-07-25 · Modified
7.1EPSS 0.004
CVE-2024-24838
WordPress Five Star Restaurant Reviews Plugin <= 2.3.5 is vulnerable to Cross Site Scripting (XSS)
Published 2024-02-05 · Modified
6.5EPSS 0.003
CVE-2024-5459
Restaurant Menu and Food Ordering <= 2.4.16 - Missing Authorization to Menu Creation
Published 2024-06-05 · Modified
4.3EPSS 0.004