๐Ÿ” CVE Alert

CVE-2026-13328

UNKNOWN 0.0

TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.

Vendor unknown
Product food menu
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown food menu

Be the first to know when new unknown vulnerabilities affecting unknown food menu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Food Menu
0 < 6.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/af15ecd8-a656-45ab-a1d4-85704d6d8051/

Credits

Vaibhav Narkhede WPScan