CVE-2025-68044

8.6

Rustaurius · Five Star Restaurant Reservations

An authorization bypass vulnerability in the Five Star Restaurant Reservations plugin allows unauthenticated attackers to manipulate user keys and gain unauthorized access to restricted functions.

Executive summary

An unauthenticated authorization bypass vulnerability in Rustaurius Five Star Restaurant Reservations poses a high risk of unauthorized data access and system manipulation.

Vulnerability

This vulnerability is a CWE-639 flaw, specifically an authorization bypass through a user-controlled key. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels within the reservation system.

Business impact

Successful exploitation of this flaw permits unauthorized users to bypass security controls, potentially leading to the exposure of sensitive reservation data or unauthorized modification of system settings. With a CVSS score of 8.6, this vulnerability is classified as High severity and represents a significant risk to the integrity and confidentiality of the affected reservation platform.

Remediation

Immediate Action: Monitor official vendor channels for the release of a security patch and apply it immediately upon availability.

Proactive Monitoring: Review application access logs for unusual patterns, such as multiple requests containing manipulated user keys or unauthorized attempts to access administrative endpoints.

Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious requests targeting the reservation system and enforce stricter access control policies at the network perimeter.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for unauthorized access, this vulnerability should be prioritized for remediation. While a specific patch is currently pending, administrators must remain vigilant and implement compensating controls to minimize the attack surface until an official fix is provided by the vendor.

More Rustaurius CVEs