The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-11-20T18:55:01.256Z

Updated: 2024-08-02T07:52:08.597Z

Reserved: 2023-10-02T15:44:20.984Z

Link: CVE-2023-5340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-20T19:15:09.723

Modified: 2023-11-27T16:32:49.050

Link: CVE-2023-5340

cve-icon Redhat

No data.