The Restaurant Cafeteria WordPress theme, up to version 0.4.6, has a security vulnerability where admin-ajax actions lack nonce and capability checks. This allows any logged-in user, including those with minimal permissions, to execute privileged operations, potentially leading to arbitrary PHP code execution via a user-supplied URL.
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.