Impact
The Restaurant Menu and Food Ordering WordPress plugin before version 2.4.12 fails to verify that a PayPal payment notification truly originates from PayPal. This omission allows an unauthenticated attacker to forge a PayPal IPN message and cause the system to mark an order as paid and completed without any actual payment, enabling financial fraud.
Affected Systems
The vulnerability affects the Restaurant Menu and Food Ordering plugin for WordPress, specifically all releases prior to 2.4.12. No vendor is publicly listed, and the issue applies to any WordPress site employing this plugin within the affected version range.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in a moderate severity category. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be through unauthenticated HTTP requests that send forged IPN payloads to the plugin’s endpoint; no privileged access or proprietary software access is required. Consequently, an adversary could exploit the flaw remotely to artificially inflate sales or bypass payment processing without authentication.
OpenCVE Enrichment