WordPress Plugin Vulnerabilities

Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR

Description

The plugin does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 19 days ago)
Added
2026-07-20 (about 18 days ago)
Last Updated
2026-07-20 (about 18 days ago)

Other