CVE-2026-57644
MotoPress · Restaurant Menu
A SQL injection vulnerability exists in the Restaurant Menu by MotoPress plugin, allowing authenticated contributors to execute arbitrary SQL commands.
Executive summary
The Restaurant Menu plugin for WordPress is vulnerable to an authenticated SQL injection, posing a significant risk of unauthorized database access and data exfiltration.
Vulnerability
This vulnerability is an SQL injection flaw that resides in the plugin's database query handling, specifically reachable by users with Contributor-level privileges. An attacker can manipulate input parameters to execute unauthorized commands against the underlying database.
Business impact
Successful exploitation allows an attacker to bypass security controls, extract sensitive information, or potentially modify site content. With a CVSS score of 8.5, this high-severity flaw carries a substantial risk of data breach and loss of site integrity, potentially leading to long-term reputational damage.
Remediation
Immediate Action: Update the Restaurant Menu plugin to the latest version provided by MotoPress as soon as a patch becomes available.
Proactive Monitoring: Review database error logs and query logs for unusual patterns or syntax that indicate attempted SQL injection attacks.
Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block common SQL injection patterns targeting WordPress plugins.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The high CVSS score of 8.5 underscores the critical nature of this vulnerability. Organizations using this plugin should prioritize the application of vendor patches immediately upon release to mitigate the risk of unauthorized database manipulation.