The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'install_plugin' function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins, which can lead to Remote Code Execution.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orderable
Orderable orderable – Wordpress Restaurant Online Ordering System And Food Ordering Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Orderable
Orderable orderable – Wordpress Restaurant Online Ordering System And Food Ordering Plugin Wordpress Wordpress wordpress |
Thu, 19 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the 'install_plugin' function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins, which can lead to Remote Code Execution. | |
| Title | Orderable <= 1.20.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-02-19T04:36:21.529Z
Updated: 2026-02-19T04:36:21.529Z
Reserved: 2026-01-15T01:29:25.748Z
Link: CVE-2026-0974
No data.
Status : Received
Published: 2026-02-19T07:17:42.700
Modified: 2026-02-19T07:17:42.700
Link: CVE-2026-0974
No data.