WordPress Plugin Vulnerabilities

TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification

Description

The plugin does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.

Proof of Concept

Affects Plugins

Fixed in 6.0.2

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Vaibhav Narkhede
Submitter
Vaibhav Narkhede
Verified
Yes

Timeline

Publicly Published
2026-08-11 (about 2 days ago)
Added
2026-08-11 (about 1 day ago)
Last Updated
2026-08-11 (about 1 day ago)

Other