MEDIUM (6.8)
    Theme

    Insecure Admin-Ajax Actions in Restaurant Cafeteria Theme Allow Arbitrary PHP Code Execution

    Published Date: 3/28/2026
    CVE ID: CVE-2025-15445

    Summary

    The Restaurant Cafeteria WordPress theme, up to version 0.4.6, has a security vulnerability where admin-ajax actions lack nonce and capability checks. This allows any logged-in user, including those with minimal permissions, to execute privileged operations, potentially leading to arbitrary PHP code execution via a user-supplied URL.

    Vulnerability Details

    In the Restaurant Cafeteria WordPress theme through version 0.4.6, several admin-ajax actions are exposed without the necessary security measures such as nonce verification and capability checks. This oversight enables any authenticated user, even at the subscriber level, to perform actions typically reserved for administrators. By exploiting this, an attacker can provide a URL to install and activate plugins that allow arbitrary PHP code execution on the server. Additionally, attackers have the ability to import demo content that could override critical site settings, potentially leading to a complete compromise of the web application's functionality and appearance. These vulnerabilities represent a significant risk, particularly if sensitive operations can be executed or if the site's configuration is overwritten without the site administrator's consent.

    Recommendations

    To mitigate this vulnerability, site administrators should immediately restrict access to admin-ajax actions to authenticated users with proper privilege checks. Implement capability and nonce verifications to ensure that only authorized users can perform specific administrative tasks. Regularly review and update WordPress themes and plugins to the latest versions.

    Available Fixes

    Last Updated: 3/31/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More