CVE Published: 21/11/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022 Source: WPScan |
Vendor: Unknown |
Product: Five Star Restaurant Reservations Status : PUBLISHED
CVE-2022-0421 Description
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments