AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15149

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Hotel Booking plugin for WordPress prior to version 2.3.3 is vulnerable due to inadequate validation of room quantities and order totals, allowing unauthenticated users to exploit this flaw to create confirmed bookings without payment or at significantly reduced prices. This vulnerability poses a risk of financial loss and service abuse for hotel operators using the affected plugin. WordPress site administrators utilizing this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-15149
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.