Filtered by vendor Fivestarplugins
                         Subscriptions
                    
                    
                
                        Filtered by product Five Star Restaurant Reservations
                         Subscriptions
                    
                    
                
                    Total
                    3 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2022-0421 | 1 Fivestarplugins | 1 Five Star Restaurant Reservations | 2025-04-30 | 6.1 Medium | 
| The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments | ||||
| CVE-2024-33596 | 1 Fivestarplugins | 1 Five Star Restaurant Reservations | 2024-11-21 | 5.3 Medium | 
| Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16. | ||||
| CVE-2021-24965 | 1 Fivestarplugins | 1 Five Star Restaurant Reservations | 2024-11-21 | 5.4 Medium | 
| The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins | ||||
                            
                                
                                
                                    Page 1 of 1.