Vulnerabilities > Fivestarplugins > Five Star Restaurant Reservations > 2.4.10

DATE CVE VULNERABILITY TITLE RISK
2022-11-21 CVE-2022-0421 Improper Encoding or Escaping of Output vulnerability in Fivestarplugins Five Star Restaurant Reservations
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings.
network
low complexity
fivestarplugins CWE-116
6.1