Lucene search

K
cveWordfenceCVE-2022-2696
HistoryNov 03, 2022 - 5:15 p.m.

CVE-2022-2696

2022-11-0317:15:27
Wordfence
web.nvd.nist.gov
29
4
restaurant
menu
food ordering system
table reservation
wordpress
vulnerability
authorization bypass
ajax actions
capability checks
nonce validation
authenticated attackers
permissions

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

25.4%

The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin’s settings and modifying the ordering system preferences.

Affected configurations

Nvd
Vulners
Node
oraclerestaurant_menu_-_food_ordering_system_-_table_reservationRange<2.3.1wordpress
VendorProductVersionCPE
oraclerestaurant_menu_-_food_ordering_system_-_table_reservation*cpe:2.3:a:oracle:restaurant_menu_-_food_ordering_system_-_table_reservation:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "gloriafood",
    "product": "Restaurant Menu – Food Ordering System – Table Reservation",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.3.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

25.4%