CyberRota Analysis
AI-GeneratedThe Five Star Restaurant Reservations WordPress plugin prior to version 2.7.23 is vulnerable due to a lack of capability checks on certain AJAX actions, enabling users with minimal booking-management roles to reset booking notification settings without proper authorization. This could lead to unauthorized changes in booking configurations, potentially disrupting restaurant operations and user experience. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.