Fivestarplugins develops a focused set of WordPress plugins serving restaurant and business listing scenarios, including restaurant menu, reservations, and business profile functionality. The recurring vulnerability patterns—cross-site scripting, cross-site request forgery, deserialization of untrusted data, and output-encoding failures—reflect the challenges of user-generated content handling and plugin integration within the WordPress ecosystem, and vulnerabilities affecting the vendor skew toward serious severity outcomes. Current exploitation activity, exposure breadth, and detailed severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fivestarplugins over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-29045CRITICAL The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart | Mar 11, 2021 | 9.8 | 47 | NO | NO |
CVE-2023-5340CRITICAL The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perfo | Nov 20, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-37985HIGH Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions. | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-25060MEDIUM The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact | Feb 21, 2022 | 5.4 | 20 | NO | NO |
CVE-2021-24965MEDIUM The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated | Jan 24, 2022 | 5.4 | 20 | NO | NO |
CVE-2024-29089MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affec | Mar 19, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-34017MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions. | Jul 25, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-24838MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue af | Feb 5, 2024 | 5.4 | 17 | NO | NO |
CVE-2022-0421MEDIUM The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated | Nov 21, 2022 | 6.1 | 17 | NO | NO |
CVE-2024-5459MEDIUM The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_ | Jun 5, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fivestarplugins.
Media articles that mention a CVE ID that affects a product developed by Fivestarplugins — matched by CVE ID, not by vendor name.