← back
CVE-2026-13328

TLP Food Menu < 6.0.2 - Unauthenticated Reservation Status Modification

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
observed exploitation
nono source reports it
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.
Affected products
Unknown · Food Menu