{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/restaurant-menu-and-food-ordering--2.4.14/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:restaurant_menu_and_food_ordering_project:restaurant_menu_and_food_ordering:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96568"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Restaurant Menu and Food Ordering (\u003c= 2.4.14)"],"_cs_severities":["medium"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Restaurant Menu and Food Ordering plugin for WordPress (versions 2.4.14 and earlier) contains a Stored Cross-Site Scripting (XSS) vulnerability. The flaw exists because the plugin fails to properly sanitize input or escape output for the 'phone_number' parameter before storing it in the database and displaying it to users. An unauthenticated attacker can exploit this by submitting a crafted HTTP request containing malicious JavaScript payloads into the plugin's data fields. When an administrative user later accesses the infected page or dashboard view where the malicious data is rendered, the script executes within their browser session. This could allow an attacker to perform actions on behalf of the administrator, such as creating new rogue accounts, changing plugin settings, or redirecting traffic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's browser. This can lead to full site compromise, unauthorized administrative actions, or the theft of session cookies. The impact is elevated given the plugin is typically used for order processing, which may contain sensitive customer or financial data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Restaurant Menu and Food Ordering plugin for WordPress to the latest version immediately to remediate the lack of input sanitization. Since there is no patch information provided in the source, users should monitor the official WordPress plugin repository for updates and disable the plugin if an immediate fix is not available.\u003c/p\u003e\n","date_modified":"2026-09-25T10:52:58Z","date_published":"2026-09-25T10:52:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96568/","summary":"The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the context of administrator sessions.","title":"Stored XSS in Restaurant Menu and Food Ordering Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-96568/"}],"language":"en","title":"CraftedSignal Threat Feed - Restaurant Menu and Food Ordering (\u003c= 2.4.14)","version":"https://jsonfeed.org/version/1.1"}