What is CVE-2026-13328?
CVE-2026-13328 is a critical vulnerability in the Food Menu WordPress plugin before version 6.0.2, which allows unauthenticated attackers to modify reservation statuses due to missing capability and ownership checks in the status update action. Users must update the plugin to version 6.0.2 or later immediately.
Azərbaycanca: CVE-2026-13328, Food Menu WordPress plaginin 6.0.2-dən əvvəlki versiyalarında aşkarlanan kritik bir boşluqdur. Bu zəiflik autentifikasiya olunmamış hücumçulara rezervasiya statuslarını dəyişməyə imkan verir, çünki vəziyyət yeniləmə əməliyyatı heç bir səlahiyyət yoxlaması tələb etmir. İstifadəçilər plaginini dərhal 6.0.2 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Who can exploit the CVE-2026-13328 vulnerability?
Unauthenticated attackers can exploit this vulnerability, meaning they can modify reservation statuses without any login.
How do I fix the CVE-2026-13328 vulnerability?
You must immediately update the Food Menu WordPress plugin to version 6.0.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.