PT-2022-18142 · WordPress · The Restaurant Menu – Food Ordering System – Table Reservation
Ptsfence
·
Published
2022-11-03
·
Updated
2026-04-08
·
CVE-2022-2696
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress versions up to, and including 2.3.0
Description
The issue allows for authorization bypass via several AJAX actions due to missing capability checks and missing nonce validation. This enables authenticated attackers with minimal permissions to perform various actions, such as modifying the plugin's settings and the ordering system preferences.
Recommendations
For versions up to, and including 2.3.0, update to a version that includes the necessary capability checks and nonce validation to prevent authorization bypass.
As a temporary workaround, consider restricting access to the AJAX actions until a patch is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Restaurant Menu – Food Ordering System – Table Reservation