Restaurant Reservations [nd-restaurant-reservations] <= 2.0 (unfixed + closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 2.0.
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 22, 2024
CVE-2024-37223 on NVD →
Restaurant Reservations <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 21, 2024
CVE-2024-37223 on NVD →
Restaurant Reservations [nd-restaurant-reservations] < 2.0 (closed)
unknown
[en] The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitr...
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Mar 7, 2024
CVE-2024-1382 on NVD →
Restaurant Reservations <= 1.9 - Directory Traversal to Authenticated (Contributor+) Local File Inclusion
high
The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary P...
- CVSS:
- 8.8
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Mar 6, 2024
CVE-2024-1382 on NVD →
Restaurant Reservations [nd-restaurant-reservations] < 1.9 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 1.8.
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Feb 12, 2024
CVE-2023-51403 on NVD →
Restaurant Reservations <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 1.8
- Fixed in:
- 1.9
- Disclosed:
- Dec 27, 2023
CVE-2023-51403 on NVD →
Restaurant Reservations <= 1.7 - SQL Injection
medium
The plugin Restaurant Reservations is vulnerable to SQL Injection via an several parameters in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addit...
- CVSS:
- 6.4
- Affected:
- up to 1.7
- Fixed in:
- 1.8
- Disclosed:
- May 31, 2022
Restaurant Reservations [nd-restaurant-reservations] < 1.8 (closed)
unknown
The plugin Restaurant Reservations is vulnerable to SQL Injection via an several parameters in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addit...
- Affected:
- up to 1.8
- Fixed in:
- 1.8
- Disclosed:
- May 31, 2022
Restaurant Reservations [nd-restaurant-reservations] < 1.5 (closed)
unknown
[en] The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Aug 30, 2019
CVE-2019-15819 on NVD →
Restaurant Reservations [nd-restaurant-reservations] < 1.5 (closed)
unknown
Unauthenticated Options Change vulnerability found by Jerome Bruandet (Nintechnet) in WordPress Restaurant Reservations plugin (versions <= 1.3).
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Aug 12, 2019
ND Restaurant Reservations <= 1.3 - Options Change
critical
The ND Restaurant Reservations plugin before 1.5 for WordPress is vulnerable to unauthenticated option changes via the nd_rst_import_settings_php_function. This allows unauthenticated attackers to change arbitrary site options, including options that can allow site takeover, such as setting the default role to administ...
- CVSS:
- 9.8
- Affected:
- up to 1.3
- Fixed in:
- 1.5
- Disclosed:
- Aug 9, 2019
CVE-2019-15819 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database