Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Food ordering and Restaurant Menu allows PHP Local File Inclusion. This issue affects WP Food ordering and Restaurant Menu: from n/a through 1.1.
CVE ID: CVE-2025-31040
CVSS Base Severity: HIGH
CVSS Base Score: 8.1
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor: NotFound
Product: WP Food ordering and Restaurant Menu
EPSS Score: 0.15% (probability of being exploited)
EPSS Percentile: 37.0% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)