What is CVE-2026-15151?
The CVE-2026-15151 vulnerability in the Five Star Restaurant Reservations WordPress plugin lacks a capability check on an AJAX action. This allows users with the lowest booking-management role to access plugin settings without authorization. Upgrading to version 2.7.23 or later is recommended to mitigate the issue.
Azərbaycanca: CVE-2026-15151 zəifliyi Five Star Restaurant Reservations WordPress pluginində aşkarlanıb, burada AJAX əməliyyatları üzərində icazə yoxlanışı aparılmır. Bu, ən aşağı səviyyəli booking-management roluna malik istifadəçilərə plaqinin parametrlərinə icazəsiz giriş imkanı verir. Təsirə məruz qalmamaq üçün plaqini 2.7.23 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which WordPress plugin is affected by CVE-2026-15151?
It affects the Five Star Restaurant Reservations plugin.
To protect against CVE-2026-15151, which version should the plugin be updated to?
It is recommended to upgrade to version 2.7.23 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.