AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15147

MEDIUM · CVSS 5.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Five Star Restaurant Reservations plugin for WordPress prior to version 2.7.23 is vulnerable due to a lack of verification for incoming payment notifications, which allows unauthenticated attackers to manipulate reservation statuses. This can lead to unauthorized confirmations of payments, potentially resulting in financial loss and reputational damage for businesses relying on this plugin. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15147
Severity
MEDIUM
CVSS
5.3
EPSS
0.13%
WordPress

Original NVD Description

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.