CVE-2022-0421: Five Star Restaurant Reservations < 2.4.12 - Unauthenticated Arbitrary Payment Status Update to Stored XSS
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0421?
CVE-2022-0421 is a vulnerability found in the Five Star Restaurant Reservations WordPress plugin before version 2.4.12.
What is the severity of CVE-2022-0421?
The severity of CVE-2022-0421 is medium, with a CVSS score of 6.1.
How does CVE-2022-0421 affect the Five Star Restaurant Reservations plugin?
CVE-2022-0421 allows unauthenticated users to change the payment status of arbitrary bookings in the Five Star Restaurant Reservations plugin.
How can an attacker exploit CVE-2022-0421?
An attacker can exploit CVE-2022-0421 by changing the payment status of arbitrary bookings without proper authorization.
What is the recommended solution to CVE-2022-0421?
To mitigate CVE-2022-0421, it is recommended to update the Five Star Restaurant Reservations plugin to version 2.4.12 or later.