CVE-2025-7013: Qrmenumpro Menu Panel

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers. This issue affects Menu Panel: through 29012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Qrmenumpro Menu Panel: up to and including 29012026

Published 2026-01-29. Last modified 2026-06-17.