CVE-2026-13328
Received Received - Intake

Unauthenticated Reservation Status Update in Food Menu WordPress Plugin

Vulnerability report for CVE-2026-13328, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: WPScan

Description

The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to unauthenticated users and gated only by a nonce that is publicly available to visitors, allowing unauthenticated attackers to change the status of arbitrary reservations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tlp food_menu to 6.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Food Menu WordPress plugin before version 6.0.2 allows unauthenticated users to change the status of any reservation due to missing capability checks and a publicly exposed nonce. Attackers can exploit this to modify reservation status without authentication.

Detection Guidance

Check if the Food Menu WordPress plugin version is 6.0.2 or below. Inspect network traffic for unauthenticated requests to the reservation-status update action using a publicly available nonce. Look for suspicious changes in reservation statuses without logged-in users.

Impact Analysis

Unauthenticated attackers could alter reservation statuses, potentially causing confusion, data integrity issues, or operational disruptions for businesses using the plugin. This could lead to incorrect booking statuses or loss of trust in the system.

Compliance Impact

This vulnerability may impact compliance by allowing unauthorized modifications to reservation data, which could violate integrity requirements in GDPR or HIPAA. Unauthorized changes to sensitive data could lead to regulatory violations.

Mitigation Strategies

Update the Food Menu WordPress plugin to version 6.0.2 or higher immediately. Review and remove any unauthorized reservation status changes. Monitor for unusual activity in reservation logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13328. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart