CVE-2026-13328 PUBLISHED

TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification

Assigner: WPScan
Reserved: 25.06.2026 Published: 13.08.2026 Updated: 13.08.2026

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.

Product Status

Vendor Unknown
Product Food Menu
Versions Default: unaffected
  • affected from 0 to 6.0.2 (excl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE