Junglewise Threat Intelligence

CVE-2026-57644: MotoPress Restaurant Menu SQL injection

CVE-2026-57644 · Severity: high · CVSS 8.5 · Published 2026-06-26

Vendors: MotoPress.

Executive brief

The Restaurant Menu by MotoPress plugin for WordPress, which is used to manage and display food menus on websites, contains a security vulnerability that could allow an attacker to access sensitive database information. By exploiting this flaw, an individual with basic contributor-level access could potentially steal customer data or other internal site information. This could lead to data breaches and unauthorized access to proprietary business information.

Technical details

A SQL Injection vulnerability exists in the Restaurant Menu by MotoPress plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 2.4.10. An authenticated attacker with 'Contributor' level permissions or higher can inject malicious SQL queries into the database. This can lead to the unauthorized retrieval of sensitive information from the WordPress database. The vulnerability was patched in version 2.4.11.

Affected products

  • jetmonsters Restaurant Menu by MotoPress <= 2.4.10

Timeline

  • 2026-05-22: other: Reported by Baikuya
  • 2026-06-26: disclosed: Early warning sent to Patchstack customers
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Patch available in version 2.4.11

References

Related threats