CVE-2026-54835 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Five Star Restaurant Menu plugin, version 2.5.2 or earlier. The vulnerability is caused by Unauthenticated Broken Access Control. The CVE was published on 2026-06-26 and modified on 2026-06-29. The vulnerability allows attackers to perform unauthorized actions. Users should update to a patched version as soon as possible. Additional [truncated]
A Missing Authorization vulnerability was discovered in the Order Tracking plugin for WordPress. This issue, tracked as CVE-2026-39602, allows attackers to exploit incorrectly configured access control security levels. The vulnerability affects the Order Tracking plugin from its inception through version 3.4.3. The plugin's security flaw enables unauthorized access due to misconfigured access control leve [truncated]