plugin

Alex Reservations Vulnerabilities

2 known security issues reported for the Alex Reservations WordPress plugin. Most recent disclosed Nov 7, 2025.

1 high 1 medium

Running Alex Reservations on your site? Check whether your installed version is affected.

Scan your site free

Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

high

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level...

CVSS:
7.2
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Nov 7, 2025

CVE-2025-12399 on NVD →

Alex Reservations: Smart Restaurant Booking <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica...

CVSS:
6.4
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jan 29, 2025

CVE-2024-13380 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database