Security Advisory

CVE-2022-0421

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-11-21 00:00:00
Last updated 2025-04-30 14:54:24
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments