VYPR

Five Star Restaurant Reservations

by Fivestarplugins

CVEs (2)

  • CVE-2022-0421MedNov 21, 2022
    risk 0.40cvss 6.1epss 0.01

    The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of…

  • CVE-2021-24965MedJan 24, 2022
    risk 0.35cvss 5.4epss 0.01

    The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as…