Impact
A missing authorization check in the Five Star Restaurant Reservations plugin allows an attacker to access protected reservation data and potentially create, read, update, or delete reservations. This vulnerability can lead to confidentiality and integrity breaches for users whose reservation information is exposed or altered.
Affected Systems
The vulnerability affects the Rustaurius Five Star Restaurant Reservations WordPress plugin versions up to and including 2.7.9. All installations of this plugin running any version from its first release through 2.7.9 are potentially impacted. The plugin is used within WordPress environments.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of <1% suggests low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need access to the WordPress site, usually through a user account with sufficient privileges, to send fraudulent HTTP requests that bypass the missing authorization checks. Based on the description, it is inferred that the attack vector is via the web interface or API endpoints of the plugin.
OpenCVE Enrichment