AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15152

MEDIUM · CVSS 5.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Hotel Booking plugin for WordPress prior to version 2.3.2 is vulnerable due to a lack of verification for payment notifications, enabling unauthenticated users to falsely mark their bookings as fully paid. This could lead to financial losses for site owners as payments may not actually be received. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15152
Severity
MEDIUM
CVSS
5.3
EPSS
0.13%
WordPress

Original NVD Description

The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.