AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13328

MEDIUM · CVSS 5.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Food Menu WordPress plugin versions prior to 6.0.2 are vulnerable due to a lack of capability and ownership checks on the reservation-status update action, which can be accessed by unauthenticated users. This flaw allows attackers to manipulate the status of any reservation, potentially leading to unauthorized changes and disruptions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-13328
Severity
MEDIUM
CVSS
5.3
EPSS
0.15%
WordPress

Original NVD Description

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.