Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Fivestarplugins Subscribe
Filtered by product Five Star Restaurant Reservations
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0421 1 Fivestarplugins 1 Five Star Restaurant Reservations 2022-11-23 N/A 6.1 MEDIUM
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
CVE-2021-24965 1 Fivestarplugins 1 Five Star Restaurant Reservations 2022-01-28 3.5 LOW 5.4 MEDIUM
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins