Simple Restaurant Menu
Simple Restaurant Menu has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Simple Restaurant Menu has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Vinit Lakra. Simple Restaurant Menu is installed on roughly 60 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.
CVE-2025-58647Simple Restaurant Menu <= 1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Simple Restaurant Menu
Author
Will.I.am
If you are designing a restaurant website using WordPress, you may be struggling with the menu section of your website. The simple restaurant menu plugin offers a simplistic approach to creating menus for restaurants, cafes, and bars. The plugin offers you the possibility to display menus on pages, posts and in sidebars using a shortcode. Features: Upload your menus Upload and categorize your menu items Feature your menu item images in a gallery Add your own custom CSS Copy and paste shortcodes to display your menu wherever you want
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C