CyberRota Analysis
AI-GeneratedThe Five Star Restaurant Reservations plugin for WordPress prior to version 2.7.23 is vulnerable due to a lack of verification for incoming payment notifications, which allows unauthenticated attackers to manipulate reservation statuses. This can lead to unauthorized confirmations of payments, potentially resulting in financial loss and reputational damage for businesses relying on this plugin. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.