Vulnerability Description
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-13328?
CVE-2026-13328 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only b...
How severe is CVE-2026-13328?
CVE-2026-13328 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13328?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.