Executive brief
The Five Star Restaurant Reservations plugin for WordPress, which manages table bookings and customer reservations, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could potentially modify reservation data or system settings without needing to log in. This could lead to disrupted restaurant operations, loss of customer booking data, or unauthorized changes to the restaurant's reservation system.
Technical details
The Five Star Restaurant Reservations plugin for WordPress (versions <= 2.7.19) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions or modify data that should be restricted to administrative users. The vulnerability is exploited via network requests without requiring any user interaction or prior authentication. The issue is resolved in version 2.7.20, which introduces the necessary authorization and nonce validation to secure the affected components.
Affected products
- Etoile Web Design Incorporated Five Star Restaurant Reservations <= 2.7.19
Timeline
- 2026-05-18: other: Reported by Vincent Sevkli
- 2026-06-17: advisory: Patchstack advisory published
- 2026-06-25: disclosed: NVD publication date
- 2026-06-25: patched: Patch confirmed available in version 2.7.20