CVE Database
/

CVE-2021-24965

Back to search

CVE-2021-24965

Published: Jan 24, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

VendorProductVersions

Unknown

Five Star Restaurant Reservations – WordPress Booking Plugin

affected
2.4.8 - < 2.4.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now