High severity8.8NVD Advisory· Published Feb 19, 2026· Updated May 16, 2026
CVE-2026-0974
CVE-2026-0974
Description
The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'install_plugin' function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins, which can lead to Remote Code Execution.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
1- Cisco to fire 4,000 staff and generously give them free training – on CiscoThe Register Security · May 14, 2026