CVE-2026-13328: Unknown Food Menu
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.
Affected products
- Unknown Food Menu: before 6.0.2 (fixed in 6.0.2)
Published 2026-08-13. Last modified 2026-08-26.