Great Restaurant Menu WP
Great Restaurant Menu WP has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (25%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
4 independent researchers contributed these findings, one record each. Great Restaurant Menu WP is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-58812Best Restaurant Menu by PriceListo <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Great Restaurant Menu WP
Author
PriceListo
What this plugin can do for you Allows to create a menu quickly for your restaurant or other business type (such as salons, gyms, etc). It comes with 5 templates out of the box and supports custom templating. Default templates are all responsive and look great on desktop, tablet, and mobile. Menu supports groups/categories, sub groups/categories, and items. Items can include item name, description, image, and price. Menu editor allows you to easily drag and drop groups and items to re-organize easily and quickly. Fully supports network/multisite websites. Adding menu to the WordPress page Upon plugin activation, a new page is created called Menu. The menu is automatically inserted on this page. If you’d like to display the menu on a different page, proceed to step 2. Create a page or go into the editing mode in an already-created page. Under Page Attributes, select “Best Restaurant Menu” as template of the page. If you want more control over it, you can instead insert the shortcode [brm_restaurant_menu]. Short code attibutes groups – With this attribute you can specify the group IDs you would like to display in the frontend by this shortcode (comma-separated). ex: [brm_restaurant_menu groups="1,4,6"]. That will display only three groups with IDs 1, 4 and 6. show_items – Whether to display the group items or not. 0 : Not to show items. Displays only the groups without related items. 1 : Show items. ex: [brm_restaurant_menu show_items="1"] view – With this attribute, you can select the style view of the menu. Available style attributes: minimalist, two-column-minimalist, fancy, colorful, and bold. ex: [brm_restaurant_menu view="colorful"]
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C