Simple Retail Menus
Simple Retail Menus has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 8.4, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high.
The most common weakness is PHP Remote File Inclusion, behind 1 of the records (50%). Other recurring categories include SQL Injection.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. Simple Retail Menus is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.7.41.
CVE-2025-69387Simple Retail Menus <= 4.2.1 - Unauthenticated Local File Inclusion
Read the full analysisVulnerability Records
Simple Retail Menus
Author
whatwouldjessedo
Perfect for salon, restaurant, and retail store websites, as well as many other applications. Simple Retail Menus lets you create and manage menu-type lists for display in a post or page. This is a free, full-featured plugin. Create as many menus as you want, add as many items as you want to any menu, add menus to any post or page on your WordPress site. It’s simple and easy to use! Just build your menus, then copy/paste the resulting ‘shortcode’ into you post or page. Example of a shortcode: [simple-retail-menu id=”1″] Plugin’s Official Site http://whatwouldjessedo.com/simple-retail-menus/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C