Executive brief
The Restaurant Menu by MotoPress plugin for WordPress, which is used to manage and display food menus on websites, contains a security flaw that allows users with low-level 'Subscriber' accounts to perform actions they should not be authorized to do. While the impact is considered low, an attacker could potentially modify certain menu settings or data. This could lead to unauthorized changes to the website's menu content or configuration.
Technical details
The Restaurant Menu by MotoPress plugin for WordPress (versions up to and including 2.4.11) is vulnerable to broken access control due to missing authorization checks (CWE-862) on certain functions. An authenticated attacker with Subscriber-level permissions can exploit this vulnerability via network requests to execute actions that should be restricted to higher-privileged users. The vulnerability allows for unauthorized data modification (Integrity impact) but does not appear to allow for data exfiltration or service disruption. As of the advisory date, no official patch has been released.
Affected products
- MotoPress (jetmonsters) Restaurant Menu by MotoPress <= 2.4.11
Timeline
- 2025-10-10: disclosed: Reported by researcher daroo
- 2026-06-26: advisory: Published by Patchstack and NVD