WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Restaurant Menu and Food Ordering

Create and maintain modern online menus for almost any kind of restaurant. Sell food and beverages online. All in one plugin.

6Reported vulnerabilities
8.8Highest CVSS score
2.4.11Latest version
2,000+Active installs

What to do now

Update Restaurant Menu and Food Ordering to 2.4.11 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 28, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-30846 High 8.8 0.7% 2.4.4 and earlier 2.4.5 March 27, 2025
CVE-2026-73400 High 8.1 0.4% 2.4.11 and earlier August 18, 2026
CVE-2026-57644 Medium 6.5 0.4% 2.4.10 and earlier 2.4.11 June 26, 2026
CVE-2025-63078 Medium 4.3 0.3% 2.4.11 and earlier June 26, 2026
CVE-2025-49914 Medium 4.3 0.3% 2.4.7 and earlier 2.4.8 November 9, 2025
CVE-2025-54038 Medium 4.3 0.1% 2.4.6 and earlier 2.4.7 July 16, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.