plugin

Nd Restaurant Reservations Vulnerabilities

11 known security issues reported for the Nd Restaurant Reservations WordPress plugin. Most recent disclosed Jul 22, 2024.

1 critical 1 high 3 medium

Running Nd Restaurant Reservations on your site? Check whether your installed version is affected.

Scan your site free

Restaurant Reservations [nd-restaurant-reservations] <= 2.0 (unfixed + closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 2.0.

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Jul 22, 2024

CVE-2024-37223 on NVD →

Restaurant Reservations <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Jun 21, 2024

CVE-2024-37223 on NVD →

Restaurant Reservations [nd-restaurant-reservations] < 2.0 (closed)

unknown

[en] The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitr...

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Mar 7, 2024

CVE-2024-1382 on NVD →

Restaurant Reservations <= 1.9 - Directory Traversal to Authenticated (Contributor+) Local File Inclusion

high

The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of the nd_rst_search shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary P...

CVSS:
8.8
Affected:
up to 1.9
Fixed in:
2.0
Disclosed:
Mar 6, 2024

CVE-2024-1382 on NVD →

Restaurant Reservations [nd-restaurant-reservations] < 1.9 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nicdark Restaurant Reservations allows Stored XSS.This issue affects Restaurant Reservations: from n/a through 1.8.

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
Feb 12, 2024

CVE-2023-51403 on NVD →

Restaurant Reservations <= 1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 1.8
Fixed in:
1.9
Disclosed:
Dec 27, 2023

CVE-2023-51403 on NVD →

Restaurant Reservations <= 1.7 - SQL Injection

medium

The plugin Restaurant Reservations is vulnerable to SQL Injection via an several parameters in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addit...

CVSS:
6.4
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
May 31, 2022

Restaurant Reservations [nd-restaurant-reservations] < 1.8 (closed)

unknown

The plugin Restaurant Reservations is vulnerable to SQL Injection via an several parameters in versions up to, and including, 1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append addit...

Affected:
up to 1.8
Fixed in:
1.8
Disclosed:
May 31, 2022

Restaurant Reservations [nd-restaurant-reservations] < 1.5 (closed)

unknown

[en] The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Aug 30, 2019

CVE-2019-15819 on NVD →

Restaurant Reservations [nd-restaurant-reservations] < 1.5 (closed)

unknown

Unauthenticated Options Change vulnerability found by Jerome Bruandet (Nintechnet) in WordPress Restaurant Reservations plugin (versions <= 1.3).

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Aug 12, 2019

ND Restaurant Reservations <= 1.3 - Options Change

critical

The ND Restaurant Reservations plugin before 1.5 for WordPress is vulnerable to unauthenticated option changes via the nd_rst_import_settings_php_function. This allows unauthenticated attackers to change arbitrary site options, including options that can allow site takeover, such as setting the default role to administ...

CVSS:
9.8
Affected:
up to 1.3
Fixed in:
1.5
Disclosed:
Aug 9, 2019

CVE-2019-15819 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database