What is CVE-2026-15149?
This vulnerability exists in the WP Hotel Booking WordPress plugin before version 2.3.3, allowing unauthenticated users to manipulate room quantities and order totals to be non-negative when placing a booking. Since the plugin relies on client-controlled cart data, attackers can create confirmed reservations for free or at an arbitrarily reduced price. Affected users should immediately update the plugin to at least version 2.3.3.
Azərbaycanca: Bu boşluq WP Hotel Booking WordPress plugin-inin 2.3.3-dən əvvəlki versiyalarında mövcuddur və autentifikasiya olunmamış istifadəçilərə otel rezervasiyası zamanı otaq sayını və sifariş məbləğini mənfi dəyərlərlə manipulyasiya edərək pulsuz və ya çox aşağı qiymətə təsdiqlənmiş sifariş yaratmağa imkan verir. Plugin müştəri tərəfindən idarə olunan `cart` məlumatlarına arxalandığı üçün bu zəiflikdən istifadə etmək mümkündür. Təsirə məruz qalan istifadəçilər dərhal plugin-i ən azı 2.3.3 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of the WP Hotel Booking plugin are affected by CVE-2026-15149?
This vulnerability exists in the WP Hotel Booking WordPress plugin before version 2.3.3.
What can an attacker achieve by exploiting CVE-2026-15149?
Unauthenticated users can manipulate room quantities and order totals to create confirmed reservations for free or at an arbitrarily reduced price.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.