CVE-2026-54835
Deferred Deferred - Pending Action
Unauthenticated Broken Access Control in Five Star Restaurant Menu

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack five_star_restaurant_menu_plugin to 2.5.3 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-54835 is a Broken Access Control vulnerability in the WordPress Five Star Restaurant Menu Plugin versions 2.5.2 and earlier.

This flaw allows unauthenticated users to perform actions that normally require higher privileges because the plugin lacks proper authorization, authentication, or nonce token checks.

The vulnerability has a CVSS score of 7.5, indicating a moderate risk level.

Impact Analysis

Because unauthenticated users can perform higher-privileged actions, this vulnerability can lead to unauthorized changes or manipulations within the affected WordPress plugin.

Such unauthorized actions could compromise the integrity of the restaurant menu data or other related functionalities, potentially disrupting business operations or damaging reputation.

Mitigation Strategies

To mitigate the CVE-2026-54835 vulnerability, you should immediately update the WordPress Five Star Restaurant Menu Plugin to version 2.5.3 or later.

Users of Patchstack can enable auto-updates for vulnerable plugins to ensure timely patching.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54835. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart