ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 25.0513
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restaurant Reservation allows Reflected XSS. This issue affects ReDi Restaurant Reservation: from n/a through 24.1209.
- Affected:
- up to 25.0513
- Fixed in:
- 25.0513
- Disclosed:
- May 23, 2025
CVE-2025-48286 on NVD →
ReDi Restaurant Reservation <= 24.1209 - Reflected Cross-Site Scripting
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 24.1209 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...
- CVSS:
- 6.1
- Affected:
- up to 24.1209
- Fixed in:
- 25.0513
- Disclosed:
- May 22, 2025
CVE-2025-48286 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 23.0212
unknown
[en] Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211.
- Affected:
- up to 23.0212
- Fixed in:
- 23.0212
- Disclosed:
- Dec 13, 2024
CVE-2023-36510 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 24.0712
unknown
[en] Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422.
- Affected:
- up to 24.0712
- Fixed in:
- 24.0712
- Disclosed:
- Nov 1, 2024
CVE-2024-38737 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 24.1015
unknown
[en] The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...
- Affected:
- up to 24.1015
- Fixed in:
- 24.1015
- Disclosed:
- Oct 17, 2024
CVE-2024-9240 on NVD →
ReDi Restaurant Reservation <= 24.0902 - Reflected Cross-Site Scripting
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...
- CVSS:
- 6.1
- Affected:
- up to 24.0902
- Fixed in:
- 24.1015
- Disclosed:
- Oct 16, 2024
CVE-2024-9240 on NVD →
ReDi Restaurant Reservation <= 24.0422 - Missing Authorization
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the redi_restaurant_admin_menu_link_new() function in versions up to, and including, 24.0422. This makes it possible for unauthenticated attackers to update settings.
- CVSS:
- 5.3
- Affected:
- up to 24.0422
- Fixed in:
- 24.0712
- Disclosed:
- Jul 11, 2024
CVE-2024-38737 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 24.0303
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.
- Affected:
- up to 24.0303
- Fixed in:
- 24.0303
- Disclosed:
- Apr 15, 2024
CVE-2024-31385 on NVD →
ReDi Restaurant Reservation <= 24.0128 - Cross-Site Request Forgery via redi_restaurant_admin_options_page()
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0128. This is due to missing or incorrect nonce validation on the redi_restaurant_admin_options_page() function. This makes it possible for unauthenticated attackers to update plugin set...
- CVSS:
- 4.3
- Affected:
- up to 24.0128
- Fixed in:
- 24.0303
- Disclosed:
- Apr 10, 2024
CVE-2024-31385 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 24.0303
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scripting (XSS).This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.
- Affected:
- up to 24.0303
- Fixed in:
- 24.0303
- Disclosed:
- Apr 10, 2024
CVE-2024-31299 on NVD →
ReDi Restaurant Reservation <= 24.0128 - Cross-Site Request Forgery via redi_restaurant_admin_options_page()
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0128. This is due to missing or incorrect nonce validation on the redi_restaurant_admin_options_page() function. This makes it possible for unauthenticated attackers to modify the plugin...
- CVSS:
- 4.3
- Affected:
- up to 24.0128
- Fixed in:
- 24.0303
- Disclosed:
- Apr 5, 2024
CVE-2024-31299 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 24.0303
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Reservation Diary ReDi Restaurant Reservation allows Reflected XSS.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.
- Affected:
- up to 24.0303
- Fixed in:
- 24.0303
- Disclosed:
- Mar 27, 2024
CVE-2024-29806 on NVD →
ReDi Restaurant Reservation <= 24.0128 - Reflected Cross-Site Scripting
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 24.0128 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...
- CVSS:
- 6.1
- Affected:
- up to 24.0128
- Fixed in:
- 24.0303
- Disclosed:
- Mar 25, 2024
CVE-2024-29806 on NVD →
ReDi Restaurant Reservation <= 23.0211 - Missing Authorization
medium
The ReDi Restaurant Reservation plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the redi_restaurant_ajax() function in versions up to, and including, 23.0211. This makes it possible for unauthenticated attackers to modify the plugin's settings
- CVSS:
- 5.3
- Affected:
- up to 23.0211
- Fixed in:
- 23.0212
- Disclosed:
- Jun 22, 2023
CVE-2023-36510 on NVD →
ReDi Restaurant Reservation – Instant Availability & Confirmation [redi-restaurant-reservation] < 21.0426
unknown
[en] The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form...
- Affected:
- up to 21.0426
- Fixed in:
- 21.0426
- Disclosed:
- May 17, 2021
CVE-2021-24299 on NVD →
ReDi Restaurant Reservation <= 21.0307 - Stored Cross-Site Scripting
high
The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill in the form to make a restaurant reservation. The form to m...
- CVSS:
- 7.2
- Affected:
- up to 21.0307
- Fixed in:
- 21.0426
- Disclosed:
- May 9, 2021
CVE-2021-24299 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database