PT-2022-13170 · WordPress · Five Star Restaurant Reservations

Krzysztof Zając

·

Published

2022-11-21

·

Updated

2023-07-04

·

CVE-2022-0421

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Five Star Restaurant Reservations WordPress plugin versions prior to 2.4.12
Description The issue allows unauthenticated users to change the payment status of arbitrary bookings due to a lack of authorization. Additionally, it enables attackers to perform Cross-Site Scripting attacks against logged-in admins viewing failed payments because of insufficient sanitization and escaping.
Recommendations For versions prior to 2.4.12, update to version 2.4.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the payment status change functionality until the update is applied. Avoid using the plugin's payment management features with untrusted users until the issue is resolved.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2022-0421

Affected Products

Five Star Restaurant Reservations