WordPress · Five Star Restaurant Reservations · CVE-2026-15151
**Name of the Vulnerable Software and Affected Versions**
Five Star Restaurant Reservations versions prior to 2.7.23
**Description**
An authorization flaw exists due to a missing capability check on an AJAX action. This allows users assigned to the lowest booking-management role, who typically lack access to the plugin settings, to reset the configured booking notification rules via the `rtb reset notifications` action.
**Recommendations**
Update Five Star Restaurant Reservations to version 2.7.23 or later.