PT-2026-67060 · WordPress · Five Star Restaurant Reservations
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Five Star Restaurant Reservations versions prior to 2.7.23
Description
An authorization flaw exists due to a missing capability check on an AJAX action. This allows users assigned to the lowest booking-management role, who typically lack access to the plugin settings, to reset the configured booking notification rules via the
rtb reset notifications action.Recommendations
Update Five Star Restaurant Reservations to version 2.7.23 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Five Star Restaurant Reservations