CVE-2025-68044: WordPress Five Star Restaurant Reservations plugin <= 2.7.4 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.8.
Other sources
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68044?
CVE-2025-68044 has been classified as a high severity vulnerability due to its potential for authorization bypass.
How do I fix CVE-2025-68044?
To fix CVE-2025-68044, update your Five Star Restaurant Reservations plugin to version 2.7.9 or later.
What are the affected versions of CVE-2025-68044?
CVE-2025-68044 affects all versions of Five Star Restaurant Reservations up to and including 2.7.8.
What impact does CVE-2025-68044 have on user data?
CVE-2025-68044 can allow unauthorized access to user data due to improperly configured access controls.
Is there a workaround for CVE-2025-68044 until it is patched?
Currently, the best workaround for CVE-2025-68044 is to disable the Five Star Restaurant Reservations plugin until an update is applied.