QID 730987

Date Published: 2023-11-30

QID 730987: WordPress Plugin Food-and-drink-menu Arbitrary Code Execution Vulnerability

Food-and-drink-menu plugin create a stylish, responsive restaurant menu and add it to your site in minutes. With the easy-to-use builder and the included layout and customization options, youll have it set up in no time.

CVE-2020-29045 : The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.

Affected Versions:
WordPress food-and-drink-menu plugin versions prior to 2.2.1

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for food-and-drink-menu Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow remote attackers to execute arbitrary code because of an unserialize operation

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to WP ERP version 2.2.1 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730987

    Software Advisories
    Advisory ID Software Component Link
    food-and-drink-menu URL Logo wordpress.org/plugins/food-and-drink-menu/#developers