Five Star Restaurant Reservations – WordPress Booking Plugin < 2.7.23 - Missing Authorization
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.7.23. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized act...
- CVSS:
- 4.3
- Affected:
- up to 2.7.23
- Fixed in:
- 2.7.23
- Disclosed:
- Aug 2, 2026
CVE-2026-15151 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.19 - Missing Authorization
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.19. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.7.19
- Fixed in:
- 2.7.20
- Disclosed:
- Jun 17, 2026
CVE-2026-54830 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.14 - Missing Authorization
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.7.14
- Fixed in:
- 2.7.15
- Disclosed:
- May 12, 2026
CVE-2026-42670 on NVD →
Five Star Restaurant Reservations <= 2.7.16 - Unauthenticated Payment Bypass via PHP Type Juggling in 'payment_id' Parameter
medium
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's stripe_pay...
- CVSS:
- 5.3
- Affected:
- up to 2.7.16
- Fixed in:
- 2.7.17
- Disclosed:
- Apr 29, 2026
CVE-2026-6498 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.9 - Missing Authorization
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.7.9
- Fixed in:
- 2.7.10
- Disclosed:
- Mar 23, 2026
CVE-2026-25327 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] <= 2.7.8 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.8.
- Affected:
- up to 2.7.8
- Fix:
- No patched version reported
- Disclosed:
- Jan 5, 2026
CVE-2025-68044 on NVD →
Five Star Restaurant Reservations <= 2.7.4 - Unauthenticated Insecure Direct Object Reference
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.4 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 2, 2026
CVE-2025-68044 on NVD →
Five Star Restaurant Reservations <= 2.7.8 - Cross-Site Request Forgery
medium
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 2.7.8
- Fixed in:
- 2.7.9
- Disclosed:
- Dec 24, 2025
CVE-2025-68601 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] <= 2.7.7 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.7.
- Affected:
- up to 2.7.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68601 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] < 2.7.7
unknown
[en] The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...
- Affected:
- up to 2.7.7
- Fixed in:
- 2.7.7
- Disclosed:
- Dec 21, 2025
CVE-2025-11496 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.7
- Disclosed:
- Dec 20, 2025
CVE-2025-11496 on NVD →
Five Star Restaurant Reservations <= 2.6.29 - Missing Authorization
medium
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.29. This makes it possible for authenticated attackers, with Booking Manager-level access and above, to per...
- CVSS:
- 4.3
- Affected:
- up to 2.6.29
- Fixed in:
- 2.6.30
- Disclosed:
- Mar 27, 2025
CVE-2025-30861 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] < 2.6.30
unknown
[en] Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.6.29.
- Affected:
- up to 2.6.30
- Fixed in:
- 2.6.30
- Disclosed:
- Mar 27, 2025
CVE-2025-30861 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] < 2.6.17
unknown
[en] Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.
- Affected:
- up to 2.6.17
- Fixed in:
- 2.6.17
- Disclosed:
- Apr 29, 2024
CVE-2024-33596 on NVD →
Five Star Restaurant Reservations <= 2.6.16 - Missing Authorization
medium
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 2.6.16. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 2.6.16
- Fixed in:
- 2.6.17
- Disclosed:
- Apr 25, 2024
CVE-2024-33596 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] < 2.6.8
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
- Affected:
- up to 2.6.8
- Fixed in:
- 2.6.8
- Disclosed:
- Jul 25, 2023
CVE-2023-34017 on NVD →
Five Star Restaurant Reservations <= 2.6.7 - Reflected Cross-Site Scripting
medium
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter_name' parameter in versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...
- CVSS:
- 6.1
- Affected:
- up to 2.6.7
- Fixed in:
- 2.6.8
- Disclosed:
- Jun 23, 2023
CVE-2023-34017 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] < 2.4.12
unknown
[en] The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could pe...
- Affected:
- up to 2.4.12
- Fixed in:
- 2.4.12
- Disclosed:
- Nov 21, 2022
CVE-2022-0421 on NVD →
Five Star Restaurant Reservations <= 2.4.11 - Missing Authorization to Stored Cross-Site Scripting
high
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the rtb_stripe_pmt_succeed AJAX action in versions up to, and including, 2.4.11. This makes it possible for unauthenticated attackers to inject malicious JavaScript, that will execute wh...
- CVSS:
- 7.2
- Affected:
- up to 2.4.11
- Fixed in:
- 2.4.12
- Disclosed:
- Oct 31, 2022
CVE-2022-0421 on NVD →
Five Star Restaurant Reservations – WordPress Booking Plugin [restaurant-reservations] < 2.4.8
unknown
[en] The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Script...
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.8
- Disclosed:
- Jan 24, 2022
CVE-2021-24965 on NVD →
Five Star Restaurant Reservations <= 2.4.7 - Subscriber+ Stored Cross-Site Scripting
medium
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting a...
- CVSS:
- 6.4
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.8
- Disclosed:
- Dec 21, 2021
CVE-2021-24965 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database