CVE-2023-5340

CVE-2023-5340: Five Star Restaurant Menu and Food Ordering < 2.4.11 - Unauthenticated PHP Object Injection

Vendor Unknown
Product Five Star Restaurant Menu and Food Ordering
Published November 20, 2023
Last update November 21, 2024

CVSS base score

What the vulnerability does

01Description

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

Key dates

02Disclosure timeline

November 20, 2023 CVE published
November 21, 2024 Record updated