CVE-2026-15151 PUBLISHED

Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications

Assigner: WPScan
Reserved: 08.07.2026 Published: 02.08.2026 Updated: 02.08.2026

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.

Product Status

Vendor Unknown
Product Five Star Restaurant Reservations
Versions Default: unaffected
  • affected from 0 to 2.7.23 (excl.)

Credits

  • Minar finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE