Restaurant Menu by MotoPress
by WordPress
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-30846 | Hig | 0.57 | 8.8 | 0.01 | Mar 27, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows PHP Local File Inclusion.This issue affects Restaurant Menu by MotoPress: from n/a through… | ||
| CVE-2026-73400 | Hig | 0.53 | 8.1 | 0.00 | Aug 18, 2026 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | ||
| CVE-2025-49914 | Med | 0.42 | 6.5 | 0.00 | Dec 18, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7. | ||
| CVE-2025-54038 | Med | 0.35 | 5.4 | 0.00 | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6. | ||
| CVE-2021-24722 | Med | 0.31 | 4.8 | 0.01 | Nov 1, 2021 | The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | ||
| CVE-2026-57644 | Hig | 0.00 | 8.5 | 0.00 | Jun 26, 2026 | Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions. | ||
| CVE-2025-63078 | Med | 0.00 | 4.3 | 0.00 | Jun 26, 2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. |
- risk 0.57cvss 8.8epss 0.01
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows PHP Local File Inclusion.This issue affects Restaurant Menu by MotoPress: from n/a through…
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
- risk 0.42cvss 6.5epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6.
- risk 0.31cvss 4.8epss 0.01
The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.