WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation, 90d75c4c6d236cccbf5ce896d3bbbcb54c29f2f7
- CVE, Research URL
- Home page URL
- Application
- Published on
- Aug 06, 2022
- Research Description
- WPCafe: Food Menu, Ordering, Reservation, and Delivery Solution – All in One Place! [wp-cafe] < 2.2.0 WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation <= 2.1.4 - Cross-Site Scripting The WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including 2.1.4 due to insufficient input sanitization and output escaping on the wpc_location_id parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected versions
-
max 2.2.0.
- Status
-
vulnerable