Sceawere

Vulnerability Detail

CVE-2026-103334UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sensitive Data Exposure in Five Star Restaurant Reservations

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Etoile Web Design Incorporated
Product
Five Star Restaurant Reservations
Attack Type
Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-05T19:17:13.543Z",
  "pubdate": "2026-10-05T19:17:13.543Z",
  "executiveSummary": "The Five Star Restaurant Reservations plugin for WordPress, developed by Etoile Web Design Incorporated, is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability. This flaw enables unauthorized entities to retrieve sensitive data embedded within application responses.\nThe vulnerability affects all versions of the product from inception through 2.7.24. The primary security impact involves the unauthorized disclosure of information that should otherwise remain internal or protected from public access.\nAn attacker can exploit this weakness by intercepting or requesting specific data streams handled by the plugin, potentially gaining access to sensitive reservations details or user information.\nThis vulnerability poses a significant risk to data privacy and regulatory compliance. It does not necessarily require complex exploit chains, as the underlying architecture fails to sanitize or restrict sensitive fields before data transmission to the client-side.\nSuccessful exploitation requires the attacker to have network access to the target application, allowing for the observation or manipulation of server responses.",
  "technicalDetails": "The vulnerability originates from the insecure handling of sensitive data within the Five Star Restaurant Reservations plugin's data output routines. Specifically, the application fails to adequately filter or sanitize sensitive information before transmitting it to the client, leading to an Insertion of Sensitive Information Into Sent Data condition.\nWhen a user or automated agent triggers a reservation-related request, the backend processes retrieve data from the underlying database. The vulnerable component fails to implement proper data-masking or access control checks, inadvertently including sensitive fields in the serialized response object or HTML output.\nThe attack flow begins when an attacker identifies the endpoint responsible for displaying or processing reservation data. By sending a crafted request to the plugin's frontend interface or an exposed API endpoint, the attacker forces the application to return a response containing embedded sensitive information. Because the plugin does not verify the requester's authorization context against the specific fields returned, the sensitive information is exposed in the plaintext response.\nThis flaw is present across all versions of the plugin up to 2.7.24. The exposure does not require administrative privileges or advanced authentication, as the data is often returned in the context of standard application interactions. The impact is a direct breach of confidentiality, where PII (Personally Identifiable Information) or operational metadata is leaked to unauthorized users.\nPost-exploitation, the attacker may harvest reservation records, customer names, contact details, or other internal metadata that was not intended for public disclosure. This information can be used for further reconnaissance, social engineering, or to compromise the privacy of customers using the reservation system. The lack of field-level access control on the server-side output buffers ensures that any data present in the database queried by these functions is at risk of being serialized and transmitted to the client."
}
CVE-2026-103334: Sensitive Data Exposure in Five Star Restaurant Reservations (HIGH Severity, CVSS: 7.5) | Sceawere