Executive brief
The Five Star Restaurant Menu plugin for WordPress, which is used to create and manage digital food and drink menus, contains a security flaw in its access control mechanisms. An unauthorized individual can exploit this vulnerability to perform actions that should be restricted to administrators or authorized staff. This could allow an attacker to modify menu content or settings without permission, potentially disrupting restaurant operations or displaying incorrect information to customers.
Technical details
The Five Star Restaurant Menu plugin (also known as food-and-drink-menu) for WordPress suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability is exploited via the network without requiring user interaction. Successful exploitation allows an attacker to modify data or settings within the plugin's scope. The issue is resolved in version 2.5.3.
Affected products
- Rustaurius (Five Star Plugins) Five Star Restaurant Menu <= 2.5.2
Timeline
- 2026-05-18: disclosed: Reported by Vincent Sevkli
- 2026-06-18: advisory: Patchstack advisory published
- 2026-06-26: patched: NVD publication and patch availability confirmed in version 2.5.3