Impact
Unauthenticated Cross Site Scripting can be injected through the Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin, allowing an attacker to execute arbitrary JavaScript in the context of a victim’s browser. This can lead to session hijacking, data theft, defacement, and other client‑side compromise associated with input validation failures (CWE-79).
Affected Systems
The vulnerability affects the RadiusTheme WordPress plugin Food Menu – Restaurant Menu & Online Ordering for WooCommerce, versions 6.0.5 and older.
Risk and Exploitability
With a CVSS score of 7.1 the problem is of high severity. Exploitation is possible from any unauthenticated user who can access the plugin’s front‑end URLs; the lack of an authenticated requirement means attackers can target visitors via malicious links or compromised site content. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the broad reach and potential impact qualify it as a significant risk.
OpenCVE Enrichment