The Five Star Restaurant Reservations WordPress plugin...
Moderate severity
Unreviewed
Published
Nov 21, 2022
to the GitHub Advisory Database
•
Updated Jul 4, 2023
Description
Published by the National Vulnerability Database
Nov 21, 2022
Published to the GitHub Advisory Database
Nov 21, 2022
Last updated
Jul 4, 2023
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
References