What is CVE-2026-15152?
CVE-2026-15152 is a critical vulnerability in the WP Hotel Booking WordPress plugin prior to version 2.3.2. It allows unauthenticated users to mark their bookings as fully paid by exploiting a lack of verification for payment notifications against the site's merchant account and the actual booking amount. Immediate update to version 2.3.2 or later is strongly recommended.
Azərbaycanca: CVE-2026-15152, WP Hotel Booking WordPress plugin-in 2.3.2-dən əvvəlki versiyalarında aşkar edilmiş kritik boşluqdur. Bu zəiflik autentifikasiya olunmamış istifadəçilərə ödəniş bildirişini manipulyasiya edərək rezervasiyalarını ödənilmiş kimi göstərməyə imkan verir. Plugin-i dərhal 2.3.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
How can I protect my site from the CVE-2026-15152 vulnerability in the WP Hotel Booking plugin?
You can protect your site by immediately updating the plugin to version 2.3.2 or later.
What does the CVE-2026-15152 vulnerability allow unauthenticated users to do?
The vulnerability allows unauthenticated users to mark their bookings as fully paid.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.