CVE-2024-13415 MEDIUM

CVE-2024-13415: Food Menu – Restaurant Menu & Online Ordering for WooCommerce <= 5.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Vendor Techlabpro1
Product Food Menu – Restaurant Menu & Online Ordering for WooCommerce
Weakness CWE-862 · Missing authorization
Published January 31, 2025
Last update April 8, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings.

Explanation of Vulnerability in Simple Terms

02Summary

The Food Menu plugin for WooCommerce versions up to 5.1.4 lacks proper authorization checks on certain functions. A logged-in user with low privileges can modify menu data or settings they should not have access to. The vulnerability requires an active user account but no special interaction from the victim.

What an attacker can do

03Attacker Capabilities

Modify restaurant menu data or plugin settings without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can alter menu items, pricing, or ordering settings, potentially disrupting business operations.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site (e.g., customer or subscriber role).

Key dates

06Disclosure timeline

January 31, 2025 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE