The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that the post ID provided to the AJAX action is indeed a menu item. This makes it possible for authenticated attackers, with subscriber-level access or higher, to modify or delete arbitrary posts.

Project Subscriptions

Vendors Products
Thingsforrestaurants Subscribe
Quick Restaurant Menu Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-12595 The Quick Restaurant Menu plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the fact that during menu item deletion/modification, the plugin does not verify that the post ID provided to the AJAX action is indeed a menu item. This makes it possible for authenticated attackers, with subscriber-level access or higher, to modify or delete arbitrary posts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Title Quick Restaurant Menu <= 2.0.2 - Insecure Direct Object Reference
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Mon, 13 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:34:24.761Z

Reserved: 2023-01-27T19:20:18.028Z

Link: CVE-2023-0550

cve-icon Vulnrichment

Updated: 2024-08-02T05:17:49.653Z

cve-icon NVD

Status : Modified

Published: 2023-01-27T21:15:11.123

Modified: 2026-04-08T19:18:00.937

Link: CVE-2023-0550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses