FiveStarPlugins records
10 published records for vendor fivestarplugins.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-862 Missing Authorization2
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2020-29045No exploit | The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operafivestarplugins · five star restaurant menu · CWE-502 | Critical9.8 | — | 30.8% | Mar 11, 2021 |
39Monitor | CVE-2023-5340No exploit | Five Star Restaurant Menu and Food Ordering < 2.4.11 - Unauthenticated PHP Object Injectionfivestarplugins · five star restaurant menu · CWE-74 | Critical9.8 | — | 1.2% | Nov 20, 2023 |
35Monitor | CVE-2023-37985No exploit | WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)fivestarplugins · five star restaurant menu · CWE-352 | High8.8 | — | 0.3% | Jul 17, 2023 |
24Monitor | CVE-2022-0421No exploit | Five Star Restaurant Reservations < 2.4.12 - Unauthenticated Arbitrary Payment Status Update to Stored XSSfivestarplugins · five star restaurant reservations · CWE-116 | Medium6.1 | — | 0.6% | Nov 21, 2022 |
24Monitor | CVE-2023-34017No exploit | WordPress Five Star Restaurant Reservations Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)fivestarplugins · five star restaurant menu · CWE-79 | Medium6.1 | — | 0.4% | Jul 25, 2023 |
21Monitor | CVE-2021-24965No exploit | Five Star Restaurant Reservations < 2.4.8 - Subscriber+ Stored Cross-Site Scriptingfivestarplugins · five star restaurant reservations · CWE-79 | Medium5.4 | — | 0.6% | Jan 24, 2022 |
21Monitor | CVE-2021-25060No exploit | Five Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Update to Stored XSSfivestarplugins · five star business profile and schema · CWE-79 | Medium5.4 | — | 0.6% | Feb 21, 2022 |
21Monitor | CVE-2024-33596No exploit | WordPress Five Star Restaurant Reservations plugin <= 2.6.16 - Broken Access Control vulnerabilityfive star plugins · five star restaurant reservations · CWE-862 | Medium5.3 | — | 0.4% | Apr 29, 2024 |
21Monitor | CVE-2024-24838No exploit | WordPress Five Star Restaurant Reviews Plugin <= 2.3.5 is vulnerable to Cross Site Scripting (XSS)fivestarplugins · five star restaurant menu · CWE-79 | Medium5.4 | — | 0.3% | Feb 5, 2024 |
17Monitor | CVE-2024-5459No exploit | Restaurant Menu and Food Ordering <= 2.4.16 - Missing Authorization to Menu Creationfivestarplugins · five star restaurant menu · CWE-862 | Medium4.3 | — | 0.4% | Jun 5, 2024 |
- CVE-2020-2904548Plan
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize opera
CriticalCVSS 9.8No exploitEPSS 31%fivestarplugins · five star restaurant menuMar 11, 2021
- CVE-2023-534039Monitor
Five Star Restaurant Menu and Food Ordering < 2.4.11 - Unauthenticated PHP Object Injection
CriticalCVSS 9.8No exploitEPSS 1%fivestarplugins · five star restaurant menuNov 20, 2023
- CVE-2023-3798535Monitor
WordPress Five Star Restaurant Menu Plugin <= 2.4.6 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%fivestarplugins · five star restaurant menuJul 17, 2023
- CVE-2022-042124Monitor
Five Star Restaurant Reservations < 2.4.12 - Unauthenticated Arbitrary Payment Status Update to Stored XSS
MediumCVSS 6.1No exploitEPSS 1%fivestarplugins · five star restaurant reservationsNov 21, 2022
- CVE-2023-3401724Monitor
WordPress Five Star Restaurant Reservations Plugin <= 2.6.7 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 6.1No exploitEPSS 0%fivestarplugins · five star restaurant menuJul 25, 2023
- CVE-2021-2496521Monitor
Five Star Restaurant Reservations < 2.4.8 - Subscriber+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%fivestarplugins · five star restaurant reservationsJan 24, 2022
- CVE-2021-2506021Monitor
Five Star Business Profile and Schema < 2.1.7 - Subscriber+ Page Creation & Settings Update to Stored XSS
MediumCVSS 5.4No exploitEPSS 1%fivestarplugins · five star business profile and schemaFeb 21, 2022
- CVE-2024-3359621Monitor
WordPress Five Star Restaurant Reservations plugin <= 2.6.16 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%five star plugins · five star restaurant reservationsApr 29, 2024
- CVE-2024-2483821Monitor
WordPress Five Star Restaurant Reviews Plugin <= 2.3.5 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%fivestarplugins · five star restaurant menuFeb 5, 2024
- CVE-2024-545917Monitor
Restaurant Menu and Food Ordering <= 2.4.16 - Missing Authorization to Menu Creation
MediumCVSS 4.3No exploitEPSS 0%fivestarplugins · five star restaurant menuJun 5, 2024