CVE-2025-68044
8.6Rustaurius · Five Star Restaurant Reservations
An authorization bypass vulnerability in the Five Star Restaurant Reservations plugin allows unauthenticated attackers to manipulate user keys and gain unauthorized access to restricted functions.
Executive summary
An unauthenticated authorization bypass vulnerability in Rustaurius Five Star Restaurant Reservations poses a high risk of unauthorized data access and system manipulation.
Vulnerability
This vulnerability is a CWE-639 flaw, specifically an authorization bypass through a user-controlled key. It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels within the reservation system.
Business impact
Successful exploitation of this flaw permits unauthorized users to bypass security controls, potentially leading to the exposure of sensitive reservation data or unauthorized modification of system settings. With a CVSS score of 8.6, this vulnerability is classified as High severity and represents a significant risk to the integrity and confidentiality of the affected reservation platform.
Remediation
Immediate Action: Monitor official vendor channels for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Review application access logs for unusual patterns, such as multiple requests containing manipulated user keys or unauthorized attempts to access administrative endpoints.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter malicious requests targeting the reservation system and enforce stricter access control policies at the network perimeter.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for unauthorized access, this vulnerability should be prioritized for remediation. While a specific patch is currently pending, administrators must remain vigilant and implement compensating controls to minimize the attack surface until an official fix is provided by the vendor.