Extension WordPress

Vulnérabilités ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

Cette page rassemble les failles publiées pour ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

8 fiches

CVE-2025-48286 Moyenne · 6,1
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 24.1209 – Reflected Cross-Site Scripting

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 24.1209 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-24.1209

Correctif

25.0513

Publication

22/05/2025

CVE-2024-9240 Moyenne · 6,1
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 24.0902 – Reflected Cross-Site Scripting

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for…

Versions affectées

*-24.0902

Correctif

24.1015

Publication

16/10/2024

CVE-2024-38737 Moyenne · 5,3
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 24.0422 – Missing Authorization

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the redi_restaurant_admin_menu_link_new() function in versions up to, and including, 24.0422. This makes it possible for unauthenticated attackers…

Versions affectées

*-24.0422

Correctif

24.0712

Publication

11/07/2024

CVE-2024-31385 Moyenne · 4,3
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 24.0128 – Cross-Site Request Forgery via redi_restaurant_admin_options_page()

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0128. This is due to missing or incorrect nonce validation on the redi_restaurant_admin_options_page() function. This makes it possible for…

Versions affectées

*-24.0128

Correctif

24.0303

Publication

10/04/2024

CVE-2024-31299 Moyenne · 4,3
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 24.0128 – Cross-Site Request Forgery via redi_restaurant_admin_options_page()

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 24.0128. This is due to missing or incorrect nonce validation on the redi_restaurant_admin_options_page() function. This makes it possible for…

Versions affectées

*-24.0128

Correctif

24.0303

Publication

05/04/2024

CVE-2024-29806 Moyenne · 6,1
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 24.0128 – Reflected Cross-Site Scripting

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 24.0128 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-24.0128

Correctif

24.0303

Publication

25/03/2024

CVE-2023-36510 Moyenne · 5,3
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 23.0211 – Missing Authorization

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the redi_restaurant_ajax() function in versions up to, and including, 23.0211. This makes it possible for…

Versions affectées

*-23.0211

Correctif

23.0212

Publication

22/06/2023

CVE-2021-24299 Élevée · 7,2
ReDi Restaurant Reservation – Instant Restaurant Booking & Table Reservation System

ReDi Restaurant Reservation <= 21.0307 – Stored Cross-Site Scripting

The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant reservations. These reservations are stored and can be listed on an 'Upcoming' page provided by the plugin. An unauthenticated user can fill…

Versions affectées

*-21.0307

Correctif

21.0426

Publication

09/05/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités