
**CVE-2026-0974** pertains to a security flaw in the **Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin** for WordPress. The core issue is a missing capability check in the `install_plugin` function, which resides in the plugin's codebase. This omission allows authenticated users with Subscriber-level access or higher to install arbitrary plugins without proper authorization. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-0974
Post summary
The Orderable WordPress plugin has a missing capability check in install_plugin, enabling authenticated users to install arbitrary plugins, revealing a significant security flaw.

