The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-4614 The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Sep 2025 01:45:00 +0900

Type Values Removed Values Added
First Time appeared Exthemes
Exthemes woocommerce Food
CPEs cpe:2.3:a:ex-themes:woocommerce_food:*:*:*:*:*:wordpress:*:* cpe:2.3:a:exthemes:woocommerce_food:*:*:*:*:*:wordpress:*:*
Vendors & Products Ex-themes
Ex-themes woocommerce Food
Exthemes
Exthemes woocommerce Food

Wed, 26 Feb 2025 06:15:00 +0900

Type Values Removed Values Added
First Time appeared Ex-themes
Ex-themes woocommerce Food
CPEs cpe:2.3:a:ex-themes:woocommerce_food:*:*:*:*:*:wordpress:*:*
Vendors & Products Ex-themes
Ex-themes woocommerce Food

Fri, 21 Feb 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Feb 2025 18:30:00 +0900

Type Values Removed Values Added
Description The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Title WooCommerce Food - Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-20T15:07:34.939Z

Reserved: 2025-01-29T20:06:53.441Z

Link: CVE-2024-13792

cve-icon Vulnrichment

Updated: 2025-02-20T15:07:26.694Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-20T10:15:10.850

Modified: 2025-09-10T16:41:41.050

Link: CVE-2024-13792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses