CyberRota Analysis
AI-GeneratedThe Food Menu WordPress plugin versions prior to 6.0.2 are vulnerable due to a lack of capability and ownership checks on the reservation-status update action, which can be accessed by unauthenticated users. This flaw allows attackers to manipulate the status of any reservation, potentially leading to unauthorized changes and disruptions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.