CVE-2025-30861: WordPress Five Star Restaurant Reservations plugin <= 2.6.29 - Broken Access Control vulnerability
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.6.29.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30861?
CVE-2025-30861 is classified as a missing authorization vulnerability affecting access control in the Five Star Restaurant Reservations plugin.
How do I fix CVE-2025-30861?
To fix CVE-2025-30861, update the Five Star Restaurant Reservations plugin to version 2.6.30 or later as it addresses the access control issues.
What versions of the Five Star Restaurant Reservations are affected by CVE-2025-30861?
CVE-2025-30861 affects all versions of the Five Star Restaurant Reservations plugin up to and including version 2.6.29.
What systems are impacted by CVE-2025-30861?
CVE-2025-30861 impacts both Rustaurius and WordPress versions of the Five Star Restaurant Reservations plugin.
Can CVE-2025-30861 lead to data exposure?
Yes, CVE-2025-30861 can lead to unauthorized access and potential data exposure due to incorrectly configured access control.