Executive brief
The Five Star Restaurant Reservations plugin for WordPress, which manages table bookings and customer payments, contains a security flaw that allows users to bypass payment requirements. An attacker could exploit this to secure reservations without completing the necessary financial transactions. This could lead to lost revenue and operational disruption for restaurant owners using the software.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the Five Star Restaurant Reservations plugin for WordPress through version 2.7.14. The flaw stems from incorrectly configured access control security levels within the plugin's reservation handling logic. An unauthenticated remote attacker can exploit this lack of authorization checks to bypass payment requirements during the booking process. This allows for the creation of confirmed reservations without valid payment. The issue is resolved in version 2.7.15.
Affected products
- Etoile Web Design Incorporated Five Star Restaurant Reservations n/a through 2.7.14
Timeline
- 2026-04-12: other: Reported by researcher Evan NR
- 2026-05-12: advisory: Patchstack advisory published
- 2026-06-02: disclosed: CVE published to NVD