Cross-site Scripting Flaw in VikRestaurants Table Reservations by e4jvikwp
CVE-2025-57968

7.1HIGH

What is CVE-2025-57968?

The VikRestaurants Table Reservations and Take-Away plugin by e4jvikwp is susceptible to a Cross-site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts into web pages that are reflected back to the user. Users accessing compromised pages may unknowingly execute harmful scripts, leading to potential data theft or session hijacking. This vulnerability affects all versions up to 1.4, highlighting the need for prompt updates and vigilant security practices.

Affected Version(s)

VikRestaurants Table Reservations and Take-Away <= 1.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

greenhats (Patchstack Alliance)
.