Loading market data...
← Back to CVE feed

CVE-2026-13328

UNKNOWN View on NVD ↗

Description

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.

Published: Aug 13, 2026 06:17 UTC Modified: Aug 13, 2026 06:17 UTC