CVE-2026-15151
LOW — CVSS 3.8Booking Manager+ Missing Authorization in WordPress Five Star Restaurant Reservations Plugin
Summary
A Missing Authorization vulnerability exists in the WordPress Five Star Restaurant Reservations plugin in versions prior to 2.7.23. The plugin does not perform a capability check on one of its AJAX actions.
Users with the lowest booking-management role, who by default cannot access the plugin's settings, can reset the site's configured booking notification rules.
Technical Details
The plugin ships a Booking Manager role intended only for handling reservations (read + manage_bookings, without manage_options). The rtb_reset_notifications AJAX handler, which restores the notification configuration to its defaults, verified a nonce but never checked that the caller was allowed to manage plugin settings.
Because the nonce is exposed on the bookings page that Booking Managers can already access, a user with that role can obtain it and invoke the settings-level action directly.
Attack vector: Authenticated (Booking Manager+) POST request to wp-admin/admin-ajax.php with action=rtb_reset_notifications and a valid nonce from the bookings page.
Impact
- Privilege boundary bypass between booking staff and site administrators
- Reset of the restaurant's custom booking notification rules without authorization
- Disruption of automated notification workflows for guests and staff
Remediation
Update Five Star Restaurant Reservations to version 2.7.23 or later, which adds the missing capability check to the notification reset action.