Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown
CVE-2022-0421
Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
0
Attacker Value
Unknown
CVE-2022-2754
Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
0
Attacker Value
Unknown
CVE-2022-2753
Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made
0
Attacker Value
Unknown
CVE-2022-29923
Disclosure Date: May 12, 2022 (last updated September 17, 2024)
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
0
Attacker Value
Unknown
CVE-2021-24965
Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
0
Attacker Value
Unknown
CVE-2019-15819
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
0