First published: Thu May 12 2022(Updated: )
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<1.4.2 | ||
Thingsforrestaurants Quick Restaurant Reservations | <1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29923 is an Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in the ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.4.1 at WordPress.
The Authenticated Reflected XSS vulnerability can be exploited when an authenticated user (admin or higher) clicks on a malicious link that contains specially crafted code.
The severity of CVE-2022-29923 is medium, with a severity value of 4.8.
Yes, a patch is available for CVE-2022-29923. You can find the patch at the following link: https://wordpress.org/plugins/quick-restaurant-reservations/#developers
The Common Weakness Enumeration (CWE) ID for CVE-2022-29923 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).