CVE-2026-15152 Details
Description
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.
A vulnerability exists in the WP Hotel Booking WordPress plugin in versions prior to 2.3.2. The issue arises because the plugin does not verify that payment notifications correspond to payments made to the site's merchant account or that the payment amount matches the booking total. This oversight allows unauthenticated users to have their bookings marked as fully paid, without any actual payment reaching the site owner.
Users are advised to update the WP Hotel Booking WordPress plugin to version 2.3.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/e2435361-0a2a-4914-b4d8-7fb28386c4d3/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| WP Hotel Booking | < 2.3.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion