Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fivestarplugins

First CVE: Mar 11, 2021Active for: 5 yearsTotal CVEs: 11
25.8
VTI Score
Low

Fivestarplugins develops a focused set of WordPress plugins serving restaurant and business listing scenarios, including restaurant menu, reservations, and business profile functionality. The recurring vulnerability patterns—cross-site scripting, cross-site request forgery, deserialization of untrusted data, and output-encoding failures—reflect the challenges of user-generated content handling and plugin integration within the WordPress ecosystem, and vulnerabilities affecting the vendor skew toward serious severity outcomes. Current exploitation activity, exposure breadth, and detailed severity counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fivestarplugins over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2021
5 years ago
Most Recent CVE
Jun 5, 2024
779 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-29045CRITICAL
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart
Mar 11, 20219.847NONO
CVE-2023-5340CRITICAL
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perfo
Nov 20, 20239.828NONO
CVE-2023-37985HIGH
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
Jul 17, 20238.824NONO
CVE-2021-25060MEDIUM
The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its bpfwp_welcome_add_contact_page and bpfwp_welcome_set_contact
Feb 21, 20225.420NONO
CVE-2021-24965MEDIUM
The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated
Jan 24, 20225.420NONO
CVE-2024-29089MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affec
Mar 19, 20246.519NONO
CVE-2023-34017MEDIUM
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
Jul 25, 20236.118NONO
CVE-2024-24838MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue af
Feb 5, 20245.417NONO
CVE-2022-0421MEDIUM
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated
Nov 21, 20226.117NONO
CVE-2024-5459MEDIUM
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_
Jun 5, 20244.315NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
73%
9%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fivestarplugins.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fivestarplugins — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fivestarplugins's Products

View all 4 CNAs →

Top CWEs