Impact
The Five Star Restaurant Reservations plugin fails to authenticate its payment notifications and does not bind the notification to the correct reservation. This flaw permits an unauthenticated attacker to forge payment messages, causing the plugin to mark any pending reservation as paid and confirmed. The consequence is a clear revenue loss and a false sense of occupied tables for the restaurant, effectively altering the service state without proper financial validation.
Affected Systems
WordPress sites that have installed the Five Star Restaurant Reservations plugin earlier than version 2.7.23 are affected. The vulnerability is tied to the plugin’s payment handling endpoint and is present in all releases prior to 2.7.23 for any vendor or distribution of the plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate threat. No EPSS score is available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The exploit requires the attacker to send a crafted payment notification to the plugin’s endpoint, which is unauthenticated and therefore easily reachable. Because the flaw bypasses payment verification, any successful exploitation would immediately result in booking confirmation for the attacker’s chosen reservation.
OpenCVE Enrichment