plugin

Redi Restaurant Reservation Vulnerabilities

16 known security issues reported for the Redi Restaurant Reservation WordPress plugin. Most recent disclosed May 23, 2025.

1 high 7 medium

Running Redi Restaurant Reservation on your site? Check whether your installed version is affected.

Scan your site free

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 25.0513

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.

Affected:
up to 25.0513
Fixed in:
25.0513
Disclosed:
May 23, 2025

CVE-2025-48286 on NVD →

ReDi Restaurant Reservation <= 24.1209 - Reflected Cross-Site Scripting

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 24.1209 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 24.1209
Fixed in:
25.0513
Disclosed:
May 22, 2025

CVE-2025-48286 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 23.0212

unknown

[en] Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211.

Affected:
up to 23.0212
Fixed in:
23.0212
Disclosed:
Dec 13, 2024

CVE-2023-36510 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 24.0712

unknown

[en] Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422.

Affected:
up to 24.0712
Fixed in:
24.0712
Disclosed:
Nov 1, 2024

CVE-2024-38737 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 24.1015

unknown

[en] The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

Affected:
up to 24.1015
Fixed in:
24.1015
Disclosed:
Oct 17, 2024

CVE-2024-9240 on NVD →

ReDi Restaurant Reservation <= 24.0902 - Reflected Cross-Site Scripting

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

CVSS:
6.1
Affected:
up to 24.0902
Fixed in:
24.1015
Disclosed:
Oct 16, 2024

CVE-2024-9240 on NVD →

ReDi Restaurant Reservation <= 24.0422 - Missing Authorization

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the redi_restaurant_admin_menu_link_new() function in versions up to, and including, 24.0422. This makes it possible for unauthenticated attackers to update settings.

CVSS:
5.3
Affected:
up to 24.0422
Fixed in:
24.0712
Disclosed:
Jul 11, 2024

CVE-2024-38737 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 24.0303

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

Affected:
up to 24.0303
Fixed in:
24.0303
Disclosed:
Apr 15, 2024

CVE-2024-31385 on NVD →

ReDi Restaurant Reservation <= 24.0128 - Cross-Site Request Forgery via redi_restaurant_admin_options_page()

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0128. This is due to missing or incorrect nonce validation on the redi_restaurant_admin_options_page() function. This makes it possible for unauthenticated attackers to update plugin set...

CVSS:
4.3
Affected:
up to 24.0128
Fixed in:
24.0303
Disclosed:
Apr 10, 2024

CVE-2024-31385 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 24.0303

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scripting (XSS).This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

Affected:
up to 24.0303
Fixed in:
24.0303
Disclosed:
Apr 10, 2024

CVE-2024-31299 on NVD →

ReDi Restaurant Reservation <= 24.0128 - Cross-Site Request Forgery via redi_restaurant_admin_options_page()

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0128. This is due to missing or incorrect nonce validation on the redi_restaurant_admin_options_page() function. This makes it possible for unauthenticated attackers to modify the plugin...

CVSS:
4.3
Affected:
up to 24.0128
Fixed in:
24.0303
Disclosed:
Apr 5, 2024

CVE-2024-31299 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 24.0303

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reservation Diary ReDi Restaurant Reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

Affected:
up to 24.0303
Fixed in:
24.0303
Disclosed:
Mar 27, 2024

CVE-2024-29806 on NVD →

ReDi Restaurant Reservation <= 24.0128 - Reflected Cross-Site Scripting

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 24.0128 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 24.0128
Fixed in:
24.0303
Disclosed:
Mar 25, 2024

CVE-2024-29806 on NVD →

ReDi Restaurant Reservation <= 23.0211 - Missing Authorization

medium

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the redi_restaurant_ajax() function in versions up to, and including, 23.0211. This makes it possible for unauthenticated attackers to modify the plugin's settings

CVSS:
5.3
Affected:
up to 23.0211
Fixed in:
23.0212
Disclosed:
Jun 22, 2023

CVE-2023-36510 on NVD →

ReDi Restaurant Reservation &#8211; Instant Availability &amp; Confirmation [redi-restaurant-reservation] < 21.0426

unknown

[en] The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form...

Affected:
up to 21.0426
Fixed in:
21.0426
Disclosed:
May 17, 2021

CVE-2021-24299 on NVD →

ReDi Restaurant Reservation <= 21.0307 - Stored Cross-Site Scripting

high

The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to m...

CVSS:
7.2
Affected:
up to 21.0307
Fixed in:
21.0426
Disclosed:
May 9, 2021

CVE-2021-24299 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database