cleantalk
Vulnerabilities and Security Researches

Restaurant Menu and Food Ordering, CVE-2026-84044

CVE, Research URL

CVE-2026-84044

Published on
Sep 04, 2026
Research Description
The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment.
Affected versions
max 2.4.12.
Status
vulnerable