CVE-2024-1382 is a Local File Inclusion vulnerability affecting all versions of the Restaurant Reservations WordPress plugin up to 1.9. Authenticated attackers with contributor-level access or higher can exploit this flaw via the nd_rst_layout attribute within the nd_rst_search shortcode. This allows for the inclusion and execution of arbitrary PHP files, leading to potential bypass of access controls, sensitive data exposure, or remote code execution. The vulnerability has a CVSS score of 8.8 (High) due to its low attack complexity and high impact on confidentiality, integrity, and availability. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0CPE matchmatch criteria | cpe:2.3:a:nicdarkthemes:restaurant_reservations:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.