Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2022-0421

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
Attacker Value
Unknown

CVE-2022-2754

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
Attacker Value
Unknown

CVE-2022-2753

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made
Attacker Value
Unknown

CVE-2022-29923

Disclosure Date: May 12, 2022 (last updated September 17, 2024)
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
Attacker Value
Unknown

CVE-2021-24965

Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins
Attacker Value
Unknown

CVE-2019-15819

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
0