Cross-Site Scripting Vulnerability in VikRestaurants by e4jvikwp
CVE-2025-57962

5.9MEDIUM

What is CVE-2025-57962?

An improper neutralization of input during web page generation allows attackers to exploit a stored XSS vulnerability in the VikRestaurants Table Reservations and Take-Away plugin by e4jvikwp. This security flaw can enable unauthorized users to inject malicious scripts, potentially compromising user data and web application integrity. The issue impacts all versions of the product up to 1.4, making it crucial for users to address this vulnerability to protect against potential exploitation.

Affected Version(s)

VikRestaurants Table Reservations and Take-Away <= 1.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

greenhats (Patchstack Alliance)
.