PT-2021-11641 · WordPress · Food-And-Drink-Menu

Nick Blundell

·

Published

2021-03-11

·

Updated

2021-03-17

·

CVE-2020-29045

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: food-and-drink-menu plugin through 2.2.0 for WordPress
Description: The issue allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm cart cookie in load cart from cookie in includes/class-cart-manager.php.
Recommendations: For versions through 2.2.0, consider disabling the load cart from cookie function in includes/class-cart-manager.php to prevent exploitation until a patch is available. Restrict access to the fdm cart cookie to minimize the risk of arbitrary code execution.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29045

Affected Products

Food-And-Drink-Menu