
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24529 is a Missing Authorization (Broken Access Control) vulnerability in the Quick Restaurant Reservations WordPress plugin by Alejandro (thingsforrestaurants). It allows unauthenticated network-based attackers to exploit incorrectly configured access control security levels, affecting all plugin versions through 1.6.7. The vulnerability was reported by researcher Legion Hunter on December 27, 2025, and publicly disclosed on January 23–26, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium), as assessed by CISA-ADP (Patchstack, NVD).
The vulnerability is classified as CWE-862 (Missing Authorization), corresponding to OWASP Top 10 category A1: Broken Access Control. The plugin fails to perform adequate authorization checks on one or more functions, allowing unauthenticated or low-privileged users to invoke actions that should be restricted to higher-privileged roles. No authentication or nonce token validation is enforced on the affected endpoint(s), enabling remote exploitation over the network with low attack complexity and no user interaction required (Patchstack, NVD).
Successful exploitation could allow an unauthenticated attacker to perform unauthorized actions on restaurant reservation data, including reading, modifying, or deleting reservations managed through the plugin. The primary impact is on integrity (CVSS integrity impact: Low), with potential operational disruption to restaurant booking workflows. Confidentiality and availability impacts are rated as none in the current CVSS assessment, though broader data exposure or operational disruption may be possible depending on plugin configuration (Patchstack).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack, NVD).
As of the disclosure date, no official patched version of the Quick Restaurant Reservations plugin is available. Site administrators should consider disabling the plugin until a security update is released by the developer. Additional mitigations include restricting user roles and permissions to the minimum necessary level, monitoring WordPress access logs for unauthorized interactions with reservation-related endpoints, and implementing network-level controls to limit exposure. Contacting the plugin developer (Alejandro / thingsforrestaurants) to request a security fix is also recommended (Patchstack).
Wordfence included this vulnerability in its weekly WordPress vulnerability report covering January 26 – February 1, 2026, indicating routine tracking by the WordPress security community. Patchstack, which discovered and disclosed the issue via researcher Legion Hunter, classified it as low priority with no impactful threat at the time of publication. No significant vendor statements or notable social media commentary beyond standard vulnerability aggregation have been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."