What is CVE-2026-15147?
The Five Star Restaurant Reservations WordPress plugin before version 2.7.23 fails to verify incoming payment notifications. This allows unauthenticated attackers to mark bookings as paid by manipulating payment details. Updating to the latest version is strongly recommended.
Azərbaycanca: WordPress üçün Five Star Restaurant Reservations plugin-in 2.7.23-dən əvvəlki versiyalarında autentifikasiya zəifliyi var. Plugin daxil olan ödəniş bildirişlərinin həqiqiliyini yoxlamır, bu da autentifikasiya olunmamış hücumçulara ödəniş məlumatlarını manipulyasiya edərək rezervasiyaları ödənilmiş kimi göstərməyə imkan verir. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Five Star Restaurant Reservations plugin are affected by CVE-2026-15147?
Versions prior to 2.7.23 are affected.
What does vulnerability CVE-2026-15147 allow an unauthenticated attacker to do?
It allows them to mark bookings as paid by manipulating payment details.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.