Impact
The WordPress Food Menu plugin versions before 6.0.2 allow attackers to alter the status of any reservation without authentication or ownership checks. The modification endpoint is exposed to unauthenticated users and is protected only by a nonce that is publicly available to all site visitors. This flaw permits arbitrary state changes to sensitive reservation data, allowing an attacker to mark reservations as confirmed, completed, or cancelled at will, potentially disrupting business operations, customer service, and financial processing.
Affected Systems
The vulnerability affects installations of the Food Menu plugin for WordPress with versions earlier than 6.0.2. No specific vendor or deeper version detail is supplied beyond the < 6.0.2 boundary, so any site using an older release of the plugin is potentially vulnerable.
Risk and Exploitability
The CVSS score is 5.3, and the EPSS score is less than 1%, indicating moderate severity and a low likelihood of exploitation. Because the flaw enables complete reservation status manipulation without needing any credentials, the potential impact is moderate. The vulnerability is not listed in CISA’s KEV catalog. While the attack vector is inferred to be remote over the public web through the reservation status endpoint, the concrete conditions for exploitation require that the endpoint is reachable and that an attacker can guess or compute the required nonce parameters, which may be trivial if a non‑encrypted public nonce is used.
OpenCVE Enrichment