What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Designful Stylish Price List – Price Table Builder & QR Code Restaurant Menu.This issue affects Stylish Price List – Price Table Builder & QR Code Restaurant Menu: from n/a through 7.0.17.
Explanation of Vulnerability in Simple Terms
02Summary
Stylish Price List versions up to 7.0.17 contain a cross-site request forgery (CSRF) vulnerability that allows an authenticated attacker to modify or delete site data without the user's knowledge. The vulnerability requires the attacker to trick a logged-in administrator into visiting a malicious page. An attacker with low privileges can alter price lists, menus, or QR code settings.
What an attacker can do
03Attacker Capabilities
Modify or delete price lists and menu data by tricking a logged-in admin into visiting a malicious page.
Potential impact on your site
04Site Impact
Unauthorized changes to restaurant menus, price lists, or QR codes without your knowledge or consent.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege account; victim must be logged in and visit attacker-controlled page.
Key dates
06Disclosure timeline
January 5, 2024
CVE published
April 28, 2026
Record updated