CVE-2026-13328
TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.
| Vendor | unknown |
| Product | food menu |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown food menu
Be the first to know when new unknown vulnerabilities affecting unknown food menu are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Food Menu
0 < 6.0.2
References
Credits
Vaibhav Narkhede WPScan