CVE-2024-1399
Last modified
CVE-2024-1399 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-1399?
How severe is CVE-2024-1399?
How do I fix CVE-2024-1399?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13982SPON IP Network Broadcast System, a digital audio transmissi…8.7
- CVE-2024-13983Inappropriate implementation in Lens in Google Chrome on iOS…6.3
- CVE-2024-13984QiAnXin TianQing Management Center versions up to and includ…10
- CVE-2024-13985A command injection vulnerability in Dahua EIMS versions pri…10
- CVE-2024-13986Nagios XI < 2024R1.3.2 contains a remote code execution vuln…8.8
- CVE-2024-13987Improper neutralization of input during web page generation …5.9
- CVE-2024-13990MicroWorld eScan AV's update mechanism failed to ensure auth…9.3
- CVE-2024-13991Huijietong Cloud Video Platform contains a path traversal vu…8.7
- CVE-2024-13992Nagios XI versions prior to < 2024R1.1 is vulnerable to a cr…5.4
- CVE-2024-13993Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a…6.1
- CVE-2024-13994Nagios XI versions prior to 2024R1.1.2 contain a missing aut…9.8
- CVE-2024-13995Nagios XI versions prior to 2024R1.1.2 may (confirmed in 202…8.8
Are you affected by CVE-2024-1399?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
