plugin

Restaurant Reservations Vulnerabilities

21 known security issues reported for the Restaurant Reservations WordPress plugin. Most recent disclosed Aug 2, 2026.

1 high 12 medium

Running Restaurant Reservations on your site? Check whether your installed version is affected.

Scan your site free

Five Star Restaurant Reservations – WordPress Booking Plugin < 2.7.23 - Missing Authorization

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.7.23. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an unauthorized act...

CVSS:
4.3
Affected:
up to 2.7.23
Fixed in:
2.7.23
Disclosed:
Aug 2, 2026

CVE-2026-15151 on NVD →

Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.19 - Missing Authorization

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.19. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.7.19
Fixed in:
2.7.20
Disclosed:
Jun 17, 2026

CVE-2026-54830 on NVD →

Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.14 - Missing Authorization

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.7.14
Fixed in:
2.7.15
Disclosed:
May 12, 2026

CVE-2026-42670 on NVD →

Five Star Restaurant Reservations <= 2.7.16 - Unauthenticated Payment Bypass via PHP Type Juggling in 'payment_id' Parameter

medium

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's stripe_pay...

CVSS:
5.3
Affected:
up to 2.7.16
Fixed in:
2.7.17
Disclosed:
Apr 29, 2026

CVE-2026-6498 on NVD →

Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.9 - Missing Authorization

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.7.9
Fixed in:
2.7.10
Disclosed:
Mar 23, 2026

CVE-2026-25327 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] <= 2.7.8 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.8.

Affected:
up to 2.7.8
Fix:
No patched version reported
Disclosed:
Jan 5, 2026

CVE-2025-68044 on NVD →

Five Star Restaurant Reservations <= 2.7.4 - Unauthenticated Insecure Direct Object Reference

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.4 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Jan 2, 2026

CVE-2025-68044 on NVD →

Five Star Restaurant Reservations <= 2.7.8 - Cross-Site Request Forgery

medium

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request...

CVSS:
4.3
Affected:
up to 2.7.8
Fixed in:
2.7.9
Disclosed:
Dec 24, 2025

CVE-2025-68601 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] <= 2.7.7 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.7.

Affected:
up to 2.7.7
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68601 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] < 2.7.7

unknown

[en] The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacker...

Affected:
up to 2.7.7
Fixed in:
2.7.7
Disclosed:
Dec 21, 2025

CVE-2025-11496 on NVD →

Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

CVSS:
6.1
Affected:
up to 2.7.5
Fixed in:
2.7.7
Disclosed:
Dec 20, 2025

CVE-2025-11496 on NVD →

Five Star Restaurant Reservations <= 2.6.29 - Missing Authorization

medium

The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.29. This makes it possible for authenticated attackers, with Booking Manager-level access and above, to per...

CVSS:
4.3
Affected:
up to 2.6.29
Fixed in:
2.6.30
Disclosed:
Mar 27, 2025

CVE-2025-30861 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] < 2.6.30

unknown

[en] Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.6.29.

Affected:
up to 2.6.30
Fixed in:
2.6.30
Disclosed:
Mar 27, 2025

CVE-2025-30861 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] < 2.6.17

unknown

[en] Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.

Affected:
up to 2.6.17
Fixed in:
2.6.17
Disclosed:
Apr 29, 2024

CVE-2024-33596 on NVD →

Five Star Restaurant Reservations <= 2.6.16 - Missing Authorization

medium

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 2.6.16. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 2.6.16
Fixed in:
2.6.17
Disclosed:
Apr 25, 2024

CVE-2024-33596 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] < 2.6.8

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.

Affected:
up to 2.6.8
Fixed in:
2.6.8
Disclosed:
Jul 25, 2023

CVE-2023-34017 on NVD →

Five Star Restaurant Reservations <= 2.6.7 - Reflected Cross-Site Scripting

medium

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filter_name' parameter in versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scri...

CVSS:
6.1
Affected:
up to 2.6.7
Fixed in:
2.6.8
Disclosed:
Jun 23, 2023

CVE-2023-34017 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] < 2.4.12

unknown

[en] The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could pe...

Affected:
up to 2.4.12
Fixed in:
2.4.12
Disclosed:
Nov 21, 2022

CVE-2022-0421 on NVD →

Five Star Restaurant Reservations <= 2.4.11 - Missing Authorization to Stored Cross-Site Scripting

high

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the rtb_stripe_pmt_succeed AJAX action in versions up to, and including, 2.4.11. This makes it possible for unauthenticated attackers to inject malicious JavaScript, that will execute wh...

CVSS:
7.2
Affected:
up to 2.4.11
Fixed in:
2.4.12
Disclosed:
Oct 31, 2022

CVE-2022-0421 on NVD →

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin [restaurant-reservations] < 2.4.8

unknown

[en] The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Script...

Affected:
up to 2.4.8
Fixed in:
2.4.8
Disclosed:
Jan 24, 2022

CVE-2021-24965 on NVD →

Five Star Restaurant Reservations <= 2.4.7 - Subscriber+ Stored Cross-Site Scripting

medium

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting a...

CVSS:
6.4
Affected:
up to 2.4.7
Fixed in:
2.4.8
Disclosed:
Dec 21, 2021

CVE-2021-24965 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database