cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forrestaurant-reservations restaurant-reservations

Direction: ascending
Jun 07, 2024

Five Star Restaurant Reservations – WordPress Booking Plugin # CVE-2021-24965

CVE, Research URL

CVE-2021-24965

Date
Jan 24, 2022
Research Description
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
Affected versions
max 2.4.8.
Status
vulnerable

Five Star Restaurant Reservations – WordPress Booking Plugin # CVE-2022-0421

CVE, Research URL

CVE-2022-0421

Date
Nov 21, 2022
Research Description
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
Affected versions
max 2.4.12.
Status
vulnerable

Five Star Restaurant Reservations – WordPress Booking Plugin # CVE-2023-34017

CVE, Research URL

CVE-2023-34017

Date
Jul 25, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
Affected versions
max 2.6.8.
Status
vulnerable

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2024-33596

CVE, Research URL

CVE-2024-33596

Date
Apr 29, 2024
Research Description
Missing Authorization vulnerability in Five Star Plugins Five Star Restaurant Reservations.This issue affects Five Star Restaurant Reservations: from n/a through 2.6.16.
Affected versions
max 2.6.17.
Status
vulnerable
Apr 03, 2025

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2025-30861

CVE, Research URL

CVE-2025-30861

Date
Mar 27, 2025
Research Description
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.6.29.
Affected versions
max 2.6.30.
Status
vulnerable
Jan 10, 2026

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2025-68601

CVE, Research URL

CVE-2025-68601

Date
Dec 24, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.7.
Affected versions
max 2.7.7.
Status
vulnerable

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2025-68044

CVE, Research URL

CVE-2025-68044

Date
Jan 05, 2026
Research Description
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.8.
Affected versions
max 2.7.8.
Status
vulnerable

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2025-11496

CVE, Research URL

CVE-2025-11496

Date
Dec 21, 2025
Research Description
The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.7.
Status
vulnerable
Mar 29, 2026

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2026-25327

CVE, Research URL

CVE-2026-25327

Date
Mar 25, 2026
Research Description
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9.
Affected versions
max 2.7.9.
Status
vulnerable
May 01, 2026

Five Star Restaurant Reservations &#8211; WordPress Booking Plugin # CVE-2026-6498

CVE, Research URL

CVE-2026-6498

Date
Apr 30, 2026
Research Description
The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's stripe_payment_intent_id property. When an unauthenticated attacker submits a request to the nopriv AJAX handler rtb_stripe_pmt_succeed before the Stripe payment intent has been created for a booking (i.e., before the JavaScript-triggered create_stripe_pmtIntnt() call has stored an intent ID in post meta), the stripe_payment_intent_id property on the booking object remains null. The comparison sanitize_text_field('') == null evaluates to TRUE in PHP loose comparison, causing the payment verification check to pass with zero actual payment. This makes it possible for unauthenticated attackers to mark any existing payment_pending booking as paid without completing a Stripe payment by submitting an empty payment_id parameter.
Affected versions
max 2.7.17.
Status
vulnerable