Product
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the context of administrator sessions.