Simple Retail Menus

Simple Retail Menus has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high.

The most common weakness is PHP Remote File Inclusion, behind 1 of the records (50%). Other recurring categories include SQL Injection.

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

2 independent researchers contributed these findings, one record each. Simple Retail Menus is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.7.41.

Strategic Overview

Avg CVSSHigh
8.4/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Simple Retail Menus vulnerabilities before they are exploited.

Most severe open issueCVSS 8.1CVE-2025-69387

Simple Retail Menus <= 4.2.1 - Unauthenticated Local File Inclusion

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv4.2.1

Simple Retail Menus

whatwouldjessedo

Author

whatwouldjessedo

3.6(7)
72/100
Last Updated
2014-03-15 (13y ago)
Active Installs
80+
Downloads
17,493
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 3.7.41
Created
2011-06-15 (16y ago)

Perfect for salon, restaurant, and retail store websites, as well as many other applications. Simple Retail Menus lets you create and manage menu-type lists for display in a post or page. This is a free, full-featured plugin. Create as many menus as you want, add as many items as you want to any menu, add menus to any post or page on your WordPress site. It’s simple and easy to use! Just build your menus, then copy/paste the resulting &#8216;shortcode’ into you post or page. Example of a shortcode: [simple-retail-menu id=”1&#8243;] Plugin’s Official Site http://whatwouldjessedo.com/simple-retail-menus/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C