CVE-2026-0658

MEDIUM

Five Star Restaurant Reservations <2.7.9 - CSRF

Title source: llm
STIX 2.1

Description

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

References (1)

Core 1
Core References
Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/6e39090e-a4b2-4c16-806f-e2b1c456fb00/

Scores

CVSS v3 4.3
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
Unknown/Five Star Restaurant Reservations < 2.7.9
Published Feb 02, 2026
Tracked Since Feb 18, 2026