fivestarplugins CVE Vulnerabilities & Metrics

Focus on fivestarplugins vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fivestarplugins Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fivestarplugins. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fivestarplugins CVEs: 8
Earliest CVE date: 11 Mar 2021, 20:15 UTC
Latest CVE date: 05 Jun 2024, 13:15 UTC

Latest CVE reference: CVE-2024-5459

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -75.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -75.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fivestarplugins CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.38

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 7
4.0-6.9 0
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS fivestarplugins CVEs

These are the five CVEs with the highest CVSS scores for fivestarplugins, sorted by severity first and recency.

All CVEs for fivestarplugins

CVE-2024-5459 fivestarplugins vulnerability CVSS: 0 05 Jun 2024, 13:15 UTC

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create menu sections, menus, food items, and new menu pages.

CVE-2024-24838 fivestarplugins vulnerability CVSS: 0 05 Feb 2024, 07:15 UTC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5.

CVE-2023-5340 fivestarplugins vulnerability CVSS: 0 20 Nov 2023, 19:15 UTC

The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

CVE-2023-34017 fivestarplugins vulnerability CVSS: 0 25 Jul 2023, 14:15 UTC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.

CVE-2023-37985 fivestarplugins vulnerability CVSS: 0 17 Jul 2023, 16:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.

CVE-2022-0421 fivestarplugins vulnerability CVSS: 0 21 Nov 2022, 11:15 UTC

The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments

CVE-2021-24965 fivestarplugins vulnerability CVSS: 3.5 24 Jan 2022, 08:15 UTC

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

CVE-2020-29045 fivestarplugins vulnerability CVSS: 7.5 11 Mar 2021, 20:15 UTC

The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.