WordPress Plugin Vulnerabilities
Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
Description
The plugin does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-20 (about 19 days ago)
Added
2026-07-20 (about 18 days ago)
Last Updated
2026-07-20 (about 18 days ago)