The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-02 06:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-15151
Mitre link : CVE-2026-15151
CVE.ORG link : CVE-2026-15151
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
